CVE-2023-50477
https://notcve.org/view.php?id=CVE-2023-50477
21 Dec 2023 — An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.js. Se descubrió un problema en la versión 0.6.6 del cliente nos, que permite a atacantes remotos escalar privilegios a través de getRPCEndpoint.js. • https://github.com/nos/client/issues/1485 •
CVE-2014-6941
https://notcve.org/view.php?id=CVE-2014-6941
11 Oct 2014 — The NOS Alive (aka pt.optimus.optimusalive2011) application 5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. La aplicación para Android NOS Alive (también conocido como pt.optimus.optimusalive2011) 5.1 no verifica los certificados X.509 de los servidores SSL, lo que permite a atacantes man-in-the-middle suplantar servidores y obtener información sensible a través de un ce... • http://www.kb.cert.org/vuls/id/220641 • CWE-310: Cryptographic Issues •
CVE-2010-0189
https://notcve.org/view.php?id=CVE-2010-0189
23 Feb 2010 — A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site. Un determinado control ActiveX en getPlus Download Manager de NOS Microsystems, (también se conoce como DLM o Downloader) versión 1.5.2.35, tal y como es usado en ... • http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx • CWE-20: Improper Input Validation •
CVE-2009-2564 – Adobe 9.x Related Service - 'getPlus_HelperSvc.exe' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2009-2564
21 Jul 2009 — NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is... • https://www.exploit-db.com/exploits/9199 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2008-5364
https://notcve.org/view.php?id=CVE-2008-5364
08 Dec 2008 — Stack-based buffer overflow in the getPlus ActiveX control in gp.ocx 1.2.2.50 in NOS Microsystems getPlus Download Manager, as used for the Adobe Reader 8.1 installation process and other downloads, allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2008-4817. Desbordamiento de búfer basado en pila en el control ActiveX getPlus en gp.ocx v1.2.2.50 en NOS Microsystems getPlus Download Manager, como el usado por el proceso de instalación de Adobe Reader v8.1 ... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=754 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •