Show filters
227 Total Results
Displaying 201-210 of 227
Sort by:
Attacker Value
Unknown

CVE-2012-4455

Disclosure Date: October 10, 2012 (last updated October 05, 2023)
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.
0
Attacker Value
Unknown

CVE-2012-4454

Disclosure Date: October 10, 2012 (last updated October 05, 2023)
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.
0
Attacker Value
Unknown

CVE-2012-3504

Disclosure Date: October 10, 2012 (last updated October 05, 2023)
The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory.
0
Attacker Value
Unknown

CVE-2010-5249

Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2012-2417

Disclosure Date: June 17, 2012 (last updated October 04, 2023)
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
0
Attacker Value
Unknown

CVE-2012-2943

Disclosure Date: May 27, 2012 (last updated October 04, 2023)
CRLF injection vulnerability in cryptographp.inc.php in Cryptographp allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the cfg parameter.
0
Attacker Value
Unknown

CVE-2011-0766

Disclosure Date: May 31, 2011 (last updated October 04, 2023)
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.
0
Attacker Value
Unknown

CVE-2007-6721

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
0
Attacker Value
Unknown

CVE-2009-0127

Disclosure Date: January 15, 2009 (last updated November 08, 2023)
M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.
0
Attacker Value
Unknown

CVE-2008-3897

Disclosure Date: September 03, 2008 (last updated October 04, 2023)
DiskCryptor 0.2.6 on Windows stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
0