ncipher records
11 published records for vendor ncipher.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2004-0063No exploit | The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a dincipher · payshield spp library | High7.5 | — | 1.3% | Feb 17, 2004 |
20Monitor | CVE-2006-1116No exploit | The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the impncipher · ncore | Medium5.0 | — | 1.6% | Mar 9, 2006 |
20Monitor | CVE-2001-0081No exploit | swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could alncipher · ncipher | Medium5.0 | — | 1.4% | Feb 12, 2001 |
20Monitor | CVE-2002-1446No exploit | The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returnsncipher · pkcs 11 library | Medium5.0 | — | 1.4% | Aug 1, 2002 |
18Monitor | CVE-2002-0941No exploit | The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, ncipher · nforce | Medium4.6 | — | 0.4% | Oct 4, 2002 |
18Monitor | CVE-2002-0940No exploit | domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does ncipher · mscapi csp | Medium4.6 | — | 0.4% | Oct 4, 2002 |
18Monitor | CVE-2002-0939No exploit | The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generancipher · mscapi csp | Medium4.6 | — | 0.3% | Oct 4, 2002 |
17Monitor | CVE-2003-1417No exploit | nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allncipher · support software · CWE-255 | Medium4.4 | — | 0.3% | Dec 31, 2003 |
10Monitor | CVE-2006-1115No exploit | nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, choosncipher · chil | Low2.6 | — | 1.2% | Mar 9, 2006 |
10Monitor | CVE-2006-1117No exploit | nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Enginencipher · dse200 document sealing engine | Low2.6 | — | 0.9% | Mar 9, 2006 |
8Monitor | CVE-2004-0320No exploit | Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the moncipher · nshield | Low2.1 | — | 0.3% | Nov 23, 2004 |
- CVE-2004-006330Monitor
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a di
HighCVSS 7.5No exploitEPSS 1%ncipher · payshield spp libraryFeb 17, 2004
- CVE-2006-111620Monitor
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the imp
MediumCVSS 5.0No exploitEPSS 2%ncipher · ncoreMar 9, 2006
- CVE-2001-008120Monitor
swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could al
MediumCVSS 5.0No exploitEPSS 1%ncipher · ncipherFeb 12, 2001
- CVE-2002-144620Monitor
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns
MediumCVSS 5.0No exploitEPSS 1%ncipher · pkcs 11 libraryAug 1, 2002
- CVE-2002-094118Monitor
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications,
MediumCVSS 4.6No exploitEPSS 0%ncipher · nforceOct 4, 2002
- CVE-2002-094018Monitor
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does
MediumCVSS 4.6No exploitEPSS 0%ncipher · mscapi cspOct 4, 2002
- CVE-2002-093918Monitor
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not genera
MediumCVSS 4.6No exploitEPSS 0%ncipher · mscapi cspOct 4, 2002
- CVE-2003-141717Monitor
nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may all
MediumCVSS 4.4No exploitEPSS 0%ncipher · support softwareDec 31, 2003
- CVE-2006-111510Monitor
nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, choos
LowCVSS 2.6No exploitEPSS 1%ncipher · chilMar 9, 2006
- CVE-2006-111710Monitor
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine
LowCVSS 2.6No exploitEPSS 1%ncipher · dse200 document sealing engineMar 9, 2006
- CVE-2004-03208Monitor
Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the mo
LowCVSS 2.1No exploitEPSS 0%ncipher · nshieldNov 23, 2004