CVE-2011-1036 – CA Internet Security Suite HIPS XML Security Database Parser Class Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2011-1036
The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods. La clase XML Security Database Parser en el control XMLSecDB ActiveX en el componente HIPSEngine en el Management Server anterior a v8.1.0.88, y el cliente anterior a v1.6.450, en CA Host-Based Intrusion Prevention System (HIPS) v8.1, que se utiliza en CA Internet Security Suite (ISS) de 2010, permite a atacantes remotos descargar un programa arbitrario en un equipo cliente, y ejecutar el mismo a través de vectores que comprenden los métodos SetXml y Save. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of CA Internet Security Suite 2010. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw exists within the XMLSecDB ActiveX control which is installed with HIPSEngine component. SetXml and Save methods are implemented insecurely and can allow creation of an arbitrary file on the victim's system. • http://secunia.com/advisories/43377 http://secunia.com/advisories/43490 http://securityreason.com/securityalert/8106 http://www.securityfocus.com/archive/1/516649/100/0/threaded http://www.securityfocus.com/archive/1/516687/100/0/threaded http://www.securityfocus.com/bid/46539 http://www.securitytracker.com/id?1025120 http://www.vupen.com/english/advisories/2011/0496 http://www.zerodayinitiative.com/advisories/ZDI-11-093 https://exchange.xforce.ibmcloud.com/vulnerabilities/65632 https •
CVE-2009-2740
https://notcve.org/view.php?id=CVE-2009-2740
kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet. kmxIds.sys anteriores a v7.3.1.18 en CA Host-Based Intrusion Prevention System (HIPS) v8.1 permite a atacantes remotos producir una denegación de servicio (caída de sistema) a través de un paquete malformado. • http://www.securityfocus.com/archive/1/505881/100/0/threaded https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=214665 • CWE-399: Resource Management Errors •
CVE-2008-2926
https://notcve.org/view.php?id=CVE-2008-2926
The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request. El Controlador kmxfw.sys en el Sistema de prevención de intrusiones basado en Host (Host-Based Intrusion Prevention System) r8 (HIPS-r8), como el utilizado en CA Internet Security Suite and Personal Firewall, no verifica de forma adecuada las peticiones IOCTL, lo que permite a usuarios locales provocar una denegación de servicio (caída del sistema) o posiblemente, obtengan privilegios a través de peticiones manipuladas. • http://secunia.com/advisories/31434 http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36559 http://www.securityfocus.com/archive/1/495397/100/0/threaded http://www.securityfocus.com/bid/30651 http://www.securitytracker.com/id?1020658 http://www.securitytracker.com/id?1020659 http://www.securitytracker.com/id?1020660 http://www.vupen.com/english/advisories/2008/2339 https://exchange.xforce.ibmcloud.com/vulnerabilities/44392 • CWE-20: Improper Input Validation •
CVE-2006-6952 – Computer Associates Personal Firewall 9.0 - HIPS Driver 'kmxfw.sys' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2006-6952
Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers. Los controladores del Computer Associates Host Intrusion Prevention System (HIPS) (1) Core kmxstart.sys 6.5.4.31 y (2) Firewall kmxfw.sys 6.5.4.10 permite a usuarios locales la obtención de privilegios mediante el uso de ciertos IOCTLs confidenciales para modificar los punteros a las llamadas a funciones. • https://www.exploit-db.com/exploits/29069 https://www.exploit-db.com/exploits/29070 http://secunia.com/advisories/22972 http://www.osvdb.org/30497 http://www.osvdb.org/30498 http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=38 http://www.securityfocus.com/archive/1/451952/100/0/threaded http://www.securityfocus.com/archive/1/452286/100/0/threaded http://www.securityfocus.com/archive/1/458040/100/200/threaded http://www.securityfoc •