Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2025-22587
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NCiphers SEO Bulk Editor allows Stored XSS.This issue affects SEO Bulk Editor: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2006-1115
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack.
0
Attacker Value
Unknown
CVE-2006-1117
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote attackers to obtain information about encryption keys and crack those keys with less effort than brute force.
0
Attacker Value
Unknown
CVE-2006-1116
Disclosure Date: March 09, 2006 (last updated February 22, 2025)
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.
0
Attacker Value
Unknown
CVE-2004-0320
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands.
0
Attacker Value
Unknown
CVE-2004-0063
Disclosure Date: February 17, 2004 (last updated February 22, 2025)
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.
0
Attacker Value
Unknown
CVE-2003-1417
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.
0
Attacker Value
Unknown
CVE-2002-0940
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).
0
Attacker Value
Unknown
CVE-2002-0939
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).
0
Attacker Value
Unknown
CVE-2002-0941
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges.
0