2 results (0.008 seconds)

CVSS: 9.3EPSS: 90%CPEs: 3EXPL: 0

The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods. La clase XML Security Database Parser en el control XMLSecDB ActiveX en el componente HIPSEngine en el Management Server anterior a v8.1.0.88, y el cliente anterior a v1.6.450, en CA Host-Based Intrusion Prevention System (HIPS) v8.1, que se utiliza en CA Internet Security Suite (ISS) de 2010, permite a atacantes remotos descargar un programa arbitrario en un equipo cliente, y ejecutar el mismo a través de vectores que comprenden los métodos SetXml y Save. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of CA Internet Security Suite 2010. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw exists within the XMLSecDB ActiveX control which is installed with HIPSEngine component. SetXml and Save methods are implemented insecurely and can allow creation of an arbitrary file on the victim's system. • http://secunia.com/advisories/43377 http://secunia.com/advisories/43490 http://securityreason.com/securityalert/8106 http://www.securityfocus.com/archive/1/516649/100/0/threaded http://www.securityfocus.com/archive/1/516687/100/0/threaded http://www.securityfocus.com/bid/46539 http://www.securitytracker.com/id?1025120 http://www.vupen.com/english/advisories/2011/0496 http://www.zerodayinitiative.com/advisories/ZDI-11-093 https://exchange.xforce.ibmcloud.com/vulnerabilities/65632 https&# •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet. kmxIds.sys anteriores a v7.3.1.18 en CA Host-Based Intrusion Prevention System (HIPS) v8.1 permite a atacantes remotos producir una denegación de servicio (caída de sistema) a través de un paquete malformado. • http://www.securityfocus.com/archive/1/505881/100/0/threaded https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=214665 • CWE-399: Resource Management Errors •