Show filters
227 Total Results
Displaying 201-210 of 227
Sort by:
Attacker Value
Unknown
CVE-2012-4455
Disclosure Date: October 10, 2012 (last updated October 05, 2023)
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.
0
Attacker Value
Unknown
CVE-2012-4454
Disclosure Date: October 10, 2012 (last updated October 05, 2023)
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.
0
Attacker Value
Unknown
CVE-2012-3504
Disclosure Date: October 10, 2012 (last updated October 05, 2023)
The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory.
0
Attacker Value
Unknown
CVE-2010-5249
Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2012-2417
Disclosure Date: June 17, 2012 (last updated October 04, 2023)
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
0
Attacker Value
Unknown
CVE-2012-2943
Disclosure Date: May 27, 2012 (last updated October 04, 2023)
CRLF injection vulnerability in cryptographp.inc.php in Cryptographp allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the cfg parameter.
0
Attacker Value
Unknown
CVE-2011-0766
Disclosure Date: May 31, 2011 (last updated October 04, 2023)
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.
0
Attacker Value
Unknown
CVE-2007-6721
Disclosure Date: March 30, 2009 (last updated October 04, 2023)
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
0
Attacker Value
Unknown
CVE-2009-0127
Disclosure Date: January 15, 2009 (last updated November 08, 2023)
M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.
0
Attacker Value
Unknown
CVE-2008-3897
Disclosure Date: September 03, 2008 (last updated October 04, 2023)
DiskCryptor 0.2.6 on Windows stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
0