CVE-2017-5571
https://notcve.org/view.php?id=CVE-2017-5571
Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en el componente lmadmin en Flexera FlexNet Publisher (también conocido como Flex License Manager) 11.14.1 y versiones anteriores, como se utiliza en Citrix License Server para Windows y el Citrix License Server VPX, permite a atacantes remotos redirigir a usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de vectores no especificados. • http://www.securityfocus.com/bid/96028 https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01 https://support.citrix.com/article/CTX219885 https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01 https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2015-8277
https://notcve.org/view.php?id=CVE-2015-8277
Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a. Múltiples desbordamientos de buffer en (1) lmgrd y (2) Vendor Daemon en Flexera FlexNet Publisher en versiones anteriores a 11.13.1.2 Security Update 1 permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado con código de operación (a) 0x107 o (b) 0x10a. • https://github.com/securifera/CVE-2015-8277-Exploit http://securitymumblings.blogspot.com/2016/02/cve-2015-8277.html http://support.citrix.com/article/CTX207824 http://www.kb.cert.org/vuls/id/485744 http://www.securityfocus.com/bid/83334 http://www.securitytracker.com/id/1035266 https://ics-cert.us-cert.gov/advisories/ICSA-18-102-02 https://ics-cert.us-cert.gov/advisories/ICSA-18-212-05 https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073133 https:// • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2011-4134
https://notcve.org/view.php?id=CVE-2011-4134
Heap-based buffer overflow in lmadmin in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allows remote attackers to execute arbitrary code via a crafted 0x2f packet. Un desbordamiento de buffer basado en memoria dinámica (montículo) en lmadmin en Flexera FLEXnet Publisher v11.10 (también conocido como FlexNet License Server Manager) permite a atacantes remotos ejecutar código de su elección mediante un paquete 0x2f modificado. • http://kb.flexerasoftware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=Q200980&sliceId=1 http://www.flexerasoftware.com/pl/12982.htm http://www.securityfocus.com/bid/48927 http://zerodayinitiative.com/advisories/ZDI-11-244 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2011-4135
https://notcve.org/view.php?id=CVE-2011-4135
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via vectors related to save, rename, and load operations on log files. NOTE: this might overlap CVE-2011-1389. Múltiples vulnerabilidades de salto de directorio en lmgrd en Flexera FLEXnet Publisher v11.10 (también conocido como FlexNet License Server Manager) permiten a atacantes remotos ejecutar código de su elección a través de vectores relacionados con las operaciones de guardar, renombrar y carga en los archivos de registro. NOTA: este problema podría superponerse a CVE-2011-1389. • http://kb.flexerasoftware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=Q200975&sliceId=1 http://secunia.com/advisories/45615 http://www.flexerasoftware.com/pl/13057.htm http://www.ibm.com/support/docview.wss?uid=swg21577760 http://www.securityfocus.com/bid/49191 http://www.zerodayinitiative.com/advisories/ZDI-11-272 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •