7 results (0.003 seconds)

CVSS: 7.0EPSS: 0%CPEs: 2EXPL: 0

25 Aug 2012 — Race condition in Blink Professional 4.6.1 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun ... • http://archives.neohapsis.com/archives/bugtraq/2010-05/0026.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

04 Jan 2012 — eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows local users to gain privileges via a Trojan horse gauntlet program in an arbitrary directory under /usr/local/. eEye Audit ID 2499 en eEye Digital Security Audits 2406 hasta 2423 para eEye Retina Network Security Scanner en HP-UX, IRIX, y Solaris, permite a usuarios locales ganar privilegios a través de un caballo de troya en un directorio de su elección bajo /usr/... • http://www.eeye.com/Resources/Security-Center/Research/Security-Advisories/AL20111108 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 15%CPEs: 2EXPL: 2

04 Nov 2009 — Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry. Desbordamiento de búfer en Retina WiFi Scanner v1.0.8.68, usado en Retina Network Security Scanner v5.10.14, permite a atacantes asistidos por el usuario provocar una denegación de servicio (caída de aplicación) o la ejecución de código de su elección... • https://www.exploit-db.com/exploits/9114 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

27 Jul 2001 — eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier. • http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 1

27 Jul 2001 — eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected. • http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 3

09 Mar 2001 — eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet. • https://www.exploit-db.com/exploits/20589 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 2

21 Sep 2000 — eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections. • https://www.exploit-db.com/exploits/20184 •