2 results (0.007 seconds)

CVSS: 7.2EPSS: 0%CPEs: 5EXPL: 0

The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request. El Controlador kmxfw.sys en el Sistema de prevención de intrusiones basado en Host (Host-Based Intrusion Prevention System) r8 (HIPS-r8), como el utilizado en CA Internet Security Suite and Personal Firewall, no verifica de forma adecuada las peticiones IOCTL, lo que permite a usuarios locales provocar una denegación de servicio (caída del sistema) o posiblemente, obtengan privilegios a través de peticiones manipuladas. • http://secunia.com/advisories/31434 http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36559 http://www.securityfocus.com/archive/1/495397/100/0/threaded http://www.securityfocus.com/bid/30651 http://www.securitytracker.com/id?1020658 http://www.securitytracker.com/id?1020659 http://www.securitytracker.com/id?1020660 http://www.vupen.com/english/advisories/2008/2339 https://exchange.xforce.ibmcloud.com/vulnerabilities/44392 • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the Server component in CA Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows remote attackers to inject arbitrary web script or HTML via requests that are written to logs for later display in the log viewer. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el componente Server de CA Host-Based Intrusion Prevention System (HIPS) versiones anteriores a 8.0.0.93 permite a atacantes remotos inyectar scripts web o HTML de su elección mediante peticiones que son escritas en ficheros de trazas para ser mostradas posteriormente en el visor de ficheros de trazas. • http://osvdb.org/37998 http://secunia.com/advisories/27301 http://securitytracker.com/id?1018839 http://supportconnectw.ca.com/public/cahips/infodocs/cahips-secnotice.asp http://www.securityfocus.com/archive/1/482536/100/0/threaded http://www.securityfocus.com/bid/26134 http://www.vupen.com/english/advisories/2007/3547 https://exchange.xforce.ibmcloud.com/vulnerabilities/37285 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •