Show filters
12 Total Results
Displaying 11-12 of 12
Sort by:
Attacker Value
Unknown
CVE-2002-1446
Disclosure Date: August 01, 2002 (last updated February 22, 2025)
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.
0
Attacker Value
Unknown
CVE-2001-0081
Disclosure Date: February 12, 2001 (last updated February 22, 2025)
swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.
0