
CVE-2007-5042
https://notcve.org/view.php?id=CVE-2007-5042
24 Sep 2007 — Outpost Firewall Pro 4.0.1025.7828 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenProcess, (5) NtOpenSection, (6) NtOpenThread, and (7) NtUnloadDriver kernel SSDT hooks, a partial regression of CVE-2006-7160. Outpost Firewall Pro 4.0.1025.7828 no valida de forma adecuada ciertos parámetros... • http://osvdb.org/45899 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2007-3086 – Agnitum Outpost Firewall 4.0 - Outpost_IPC_HDR Local Denial of Service
https://notcve.org/view.php?id=CVE-2007-3086
06 Jun 2007 — Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex. Bloqueo de recurso crítico no restringido en Agnitum Outpost Firewall PRO 4.0 1007.591.145 y anteriores permite a atacantes remotos provocar una denegación de servicio (cuelgue del sistema) capturando el mutex outpost_ipc_hdr. • https://www.exploit-db.com/exploits/30139 •

CVE-2006-7160
https://notcve.org/view.php?id=CVE-2006-7160
07 Mar 2007 — The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial of service (crash) via invalid arguments to the (1) NtAssignProcessToJobObject,, (2) NtCreateKey, (3) NtCreateThread, (4) NtDeleteFile, (5) NtLoadDriver, (6) NtOpenProcess, (7) NtProtectVirtualMemory, (8) NtReplaceKey, (9) NtTerminateProcess, (10) NtTerminateThread, (11) NtUnloadDriver, and (12) NtWriteVirtualMemory functions. El ... • http://secunia.com/advisories/22913 • CWE-20: Improper Input Validation •

CVE-2007-0333 – Outpost Firewall PRO 4.0 - Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2007-0333
18 Jan 2007 — Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys. Agnitum Outpost Firewall PRO 4.0 permite a un usuario local evitar las restricciones de acceso insertando un ontrolador caballo de troya dentro del directorio de productos de instalación a través de la creación de enlaces... • https://www.exploit-db.com/exploits/29465 •

CVE-2006-5721 – Outpost Firewall PRO 4.0 - Local Denial of Service
https://notcve.org/view.php?id=CVE-2006-5721
04 Nov 2006 — The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (system crash) via an invalid argument to the DeviceIoControl function that triggers an invalid memory operation. El dispositivo \Device\SandBox en Outpost Firewall PRO 4.0 (964.582.059) permite a un usuario local provocar denegación de servicio (caida del sistema) a través de un argumento inválido a la función DeviceIoControl que dispara una operación inválida de memoria. • https://www.exploit-db.com/exploits/28894 •

CVE-2006-3696 – Agnitum Outpost Firewall 3.5.631 - 'FiltNT.SYS' Local Denial of Service
https://notcve.org/view.php?id=CVE-2006-3696
19 Jul 2006 — filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe. filtnt.sys en Outpost Firewall Pro before 3.51.759.6511 (462) permite a usuarios locales provocar denegación de servicio (caida) a través de argumentos en mshta.exe. • https://www.exploit-db.com/exploits/28232 •

CVE-2006-3697
https://notcve.org/view.php?id=CVE-2006-3697
19 Jul 2006 — Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and execute commands (a) via the "open folder" option when no instance of explorer.exe is running, possibly related to the ShellExecute API function; or (b) by overwriting a batch file through the "S... • http://secunia.com/advisories/21088 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2004-2472
https://notcve.org/view.php?id=CVE-2004-2472
31 Dec 2004 — Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro. • http://secunia.com/advisories/11601 •