CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2003-1417 MEDIUM

nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to g…

CVSS 4.4 EPSS 0.28% Oct 20, 2007
CVE-2006-1117 LOW

nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source M…

CVSS 2.6 EPSS 0.92% Mar 9, 2006
CVE-2006-1116 MEDIUM

The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a…

CVSS 5.0 EPSS 1.57% Mar 9, 2006
CVE-2006-1115 LOW

nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameter…

CVSS 2.6 EPSS 1.18% Mar 9, 2006
CVE-2004-0320 LOW

Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time mem…

CVSS 2.1 EPSS 0.34% Sep 1, 2004
CVE-2004-0063 HIGH

The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code…

CVSS 7.5 EPSS 1.33% Sep 1, 2004
CVE-2002-1446 MEDIUM

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status…

CVSS 5.0 EPSS 1.35% Sep 1, 2004
CVE-2002-0941 MEDIUM

The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphra…

CVSS 4.6 EPSS 0.40% Apr 2, 2003
CVE-2002-0940 MEDIUM

domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Op…

CVSS 4.6 EPSS 0.40% Aug 31, 2002
CVE-2002-0939 MEDIUM

The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Car…

CVSS 4.6 EPSS 0.35% Aug 31, 2002
CVE-2001-0081 MEDIUM

swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to ga…

CVSS 5.0 EPSS 1.39% May 7, 2001

Showing 1 to 11 CVEs · page 1