Known Vulnerabilities for products from Ncipher

Listed below are 11 of the newest known vulnerabilities associated with the vendor "Ncipher".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2006-1117 json nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document... Not Provided 2006-03-09 2025-04-03
CVE-2006-1116 json The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a messa... Not Provided 2006-03-09 2025-04-03
CVE-2006-1115 json nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup pa... Not Provided 2006-03-09 2025-04-03
CVE-2004-0320 json Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets s... Not Provided 2004-11-23 2025-04-03
CVE-2004-0063 json The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the H... Not Provided 2004-02-17 2025-04-03
CVE-2003-1417 json nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key... Not Provided 2003-12-31 2025-04-03
CVE-2002-1446 json The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 an... Not Provided 2002-08-01 2025-04-03
CVE-2002-0941 json The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other... Not Provided 2002-10-04 2025-04-03
CVE-2002-0940 json domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests... Not Provided 2002-10-04 2025-04-03
CVE-2002-0939 json The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but ... Not Provided 2002-10-04 2025-04-03
CVE-2001-0081 json swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user,... Not Provided 2001-02-12 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report