CVE Tools

Ncipher

10 CVEs tracked since 2001. Since May 2001, none of them reached CISA KEV.

Ncipher CVEs per month

May 2001 to Mar 2006. Point at a month, or focus the strip and use the arrow keys.
Ncipher CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2001-0510
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-0820
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-0410
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-0930
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-0330

Products

The products that kept showing up in Ncipher's monthly top three, with their CVEs summed over those months.

  1. Mscapi Csp21 month
  2. Ncore21 month
  3. Nshield22 months
  4. Chil11 month
  5. DSE200 Document Sealing Engine11 month
  6. Ncipher11 month
  7. Nforce11 month
  8. Payshield Spp Library11 month
  9. Pkcs 11 Library11 month

Latest CVEs

The 11 most recently published vulnerabilities affecting Ncipher.

  1. CVE-2003-1417nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (...4.4
  2. CVE-2006-1116The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attac...5.0
  3. CVE-2006-1117nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other...2.6
  4. CVE-2006-1115nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crac...2.6
  5. CVE-2004-0063The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to ma...7.5
  6. CVE-2004-0320Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands.2.1
  7. CVE-2002-1446The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signat...5.0
  8. CVE-2002-0941The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application...4.6
  9. CVE-2002-0939The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protec...4.6
  10. CVE-2002-0940domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lo...4.6
  11. CVE-2001-0081swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.5.0

The record

Peak rank
#36 in Aug 2002
Busiest month shown
Sep 2004, 3 CVEs
Months with a KEV entry
0 since May 2001
Monthly snapshots
5 since 2001
Ncipher's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store