Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-0197

Disclosure Date: February 27, 2024 (last updated February 28, 2024)
A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
0
Attacker Value
Unknown

CVE-2021-32928

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstaller fails to close Port 1947.
Attacker Value
Unknown

CVE-2019-18232

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using symbolic links, leading to a privilege escalation. This vulnerability could also be used by an attacker to execute a malicious DLL, which could impact the integrity and availability of the system.
Attacker Value
Unknown

CVE-2019-8283

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.
Attacker Value
Unknown

CVE-2019-8282

Disclosure Date: June 07, 2019 (last updated November 27, 2024)
Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one.
Attacker Value
Unknown

CVE-2018-8900

Disclosure Date: May 02, 2018 (last updated November 26, 2024)
The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown

CVE-2018-6304

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service
0
Attacker Value
Unknown

CVE-2018-6305

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
Denial of service in Gemalto's Sentinel LDK RTE version before 7.65
0
Attacker Value
Unknown

CVE-2017-12821

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution.
0
Attacker Value
Unknown

CVE-2017-12820

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
0