Signkorea maintains a narrow product line centered on digital certificate and authentication services, including ActiveX controls and certificate-management utilities that support Korean PKI infrastructure. The observed vulnerabilities reflect the limited disclosure history and assessment granularity typical of this vendor's domain, with weakness characterizations that remain preliminary. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Signkorea over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1955HIGH Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arg | Apr 11, 2007 | 10.0 | 26 | NO | NO |
CVE-2018-5202HIGH SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded | Dec 21, 2018 | 7.8 | 25 | NO | NO |
CVE-2007-1722HIGH Buffer overflow in the DownloadCertificateExt function in SignKorea SKCommAX ActiveX control module 7.2.0.2 and 3280 6.6.0.1 allows remote attackers to execute arbitrary code via a | Mar 28, 2007 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Signkorea.
Media articles that mention a CVE ID that affects a product developed by Signkorea — matched by CVE ID, not by vendor name.