8 results (0.008 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges. En las versiones anteriores a Liton SP1 (11.14.1.1) de FlaxNet Publisher ejecutando FlaxNet Publisher Licensing Service en Windows, un error de limites relacionado al nombre de la tubería dentro de el FlaxNet Publisher Licensing Service puede ser explotado provocando una lectura de memoria fuera de los límites y consecuentemente ejecutar un código aleatorio en los privilegios de SYSTEM. • https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01 https://secuniaresearch.flexerasoftware.com/advisories/76368 https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager https://www.schneider-electric.com/en/download/document/SEVD-2018-046-01 https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01 https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated privileges. Un error al manejar ciertos comandos y servicios externos relacionados con el Inventory Agent y Beacon de FlexNet del Flexera Software FlexNet Manager Suite versiones 2017 anterior a 2017 R1 y versiones 2014 R3 hasta 2016 R1 SP1, pueden ser explotados para alcanzar privilegios elevados. • https://secuniaresearch.flexerasoftware.com/advisories/76223 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en el componente lmadmin en Flexera FlexNet Publisher (también conocido como Flex License Manager) 11.14.1 y versiones anteriores, como se utiliza en Citrix License Server para Windows y el Citrix License Server VPX, permite a atacantes remotos redirigir a usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de vectores no especificados. • http://www.securityfocus.com/bid/96028 https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01 https://support.citrix.com/article/CTX219885 https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01 https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

Untrusted search path vulnerability in Flexera InstallAnywhere allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. Vulnerabilidad de búsqueda de ruta no confiable en Flexera InstallAnywhere permite a usuarios locales obtener privilegios a través de un Troyano DLL en el directorio de trabajo actual de un archivo ejecutable lanzador de instalación. • http://www-01.ibm.com/support/docview.wss?uid=swg21984949 http://www-01.ibm.com/support/docview.wss?uid=swg21985483 http://www.securityfocus.com/bid/90979 http://www.securitytracker.com/id/1036478 https://flexeracommunity.force.com/customer/articles/INFO/Best-Practices-to-Avoid-Windows-Setup-Launcher-Executable-Issues •

CVSS: 10.0EPSS: 90%CPEs: 1EXPL: 1

Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a. Múltiples desbordamientos de buffer en (1) lmgrd y (2) Vendor Daemon en Flexera FlexNet Publisher en versiones anteriores a 11.13.1.2 Security Update 1 permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado con código de operación (a) 0x107 o (b) 0x10a. • https://github.com/securifera/CVE-2015-8277-Exploit http://securitymumblings.blogspot.com/2016/02/cve-2015-8277.html http://support.citrix.com/article/CTX207824 http://www.kb.cert.org/vuls/id/485744 http://www.securityfocus.com/bid/83334 http://www.securitytracker.com/id/1035266 https://ics-cert.us-cert.gov/advisories/ICSA-18-102-02 https://ics-cert.us-cert.gov/advisories/ICSA-18-212-05 https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073133 https:// • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •