7 results (0.007 seconds)

CVSS: 6.9EPSS: 0%CPEs: 3EXPL: 0

Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition before 9.23 Build 18 allow local users to gain privileges via a Trojan horse (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, or (4) ncpmon2.dll file in the current working directory, as demonstrated by a directory that contains a .pcf or .spd file. NOTE: some of these details are obtained from third party information. Múltiples vulnerabilidades de ruta de búsqueda no confiable en NCP Secure Enterprise Client anterior a 9.21 Build 68, Entry Client anterior a 9.23 Build 18, y Secure Client - Juniper Edition anterior a 9.23 Build 18 permite a usuarios locales obtener privilegios a través de un caballo de troya (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, o (4) Archivo ncpmon2.dll en el directorio de trabajo actual, como lo demuestra un directorio que contiene un pcf. o. spd. NOTA: algunos de estos detalles han sido obtenidos a partir de información de terceros. • http://secunia.com/advisories/41388 http://www.ncp-e.com/fileadmin/pdf/service_support/NCP_Client_Vulnerability_Statement_EN.pdf •

CVSS: 1.2EPSS: 0%CPEs: 1EXPL: 0

NCP Secure Enterprise Client (aka VPN/PKI client) 8.30 Build 59, and possibly earlier versions, when the Link Firewall and Personal Firewall are both configured to block all inbound and outbound network traffic, allows context-dependent attackers to send inbound UDP traffic with source port 67 and destination port 68, and outbound UDP traffic with source port 68 and destination port 67. NCP Secure Enterprise Client (también conocido como VPN/PKI client) 8.30 Build 59, y posiblemente anteriores versiones, cuando cuando el cortafuegos de enlace y el personal (Link FireWall y Personal FireWall) son ambos configurados para bloquear todo el tráfico de red de entrada y salida, permite a atacantes dependientes del contexto enviar tráfico UDP de entrada con un puerto fuente 67 y un puerto de destino 68, y tráfico de salida UDP con un puerto fuente 68 y puerto de destino 67. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047547.html https://exchange.xforce.ibmcloud.com/vulnerabilities/27484 •

CVSS: 4.6EPSS: 0%CPEs: 1EXPL: 0

Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html http://secunia.com/advisories/19082 http://www.securityfocus.com/archive/1/426480/100/0/threaded http://www.securityfocus.com/bid/16906 https://exchange.xforce.ibmcloud.com/vulnerabilities/25242 •

CVSS: 4.6EPSS: 0%CPEs: 1EXPL: 0

NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass security protections and configure privileged options via a long argument to ncpmon.exe, which provides access to alternate privileged menus, possibly due to a buffer overflow. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html http://secunia.com/advisories/19082 http://www.securityfocus.com/archive/1/426480/100/0/threaded http://www.securityfocus.com/bid/16906 https://exchange.xforce.ibmcloud.com/vulnerabilities/25243 •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000. NOTE: this issue was reported as a buffer overflow, but that term usually does not apply in flooding attacks. NCP Network Communication Secure Client 8.11 Build 146 y posiblemente otras versiones, permite a usuarios locales provocar una denegación de servicio (uso de memoria y utilización de cpu) a través de una inundación de datagramas UDP arbitrarios de los puertos 0 a 65000. NOTA: este caso fue reportado como un desbordamiento de buffer, pero ese término no se aplica por lo general en ataques de inundación. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html http://secunia.com/advisories/19082 http://www.securityfocus.com/archive/1/426480/100/0/threaded http://www.securityfocus.com/bid/16906 https://exchange.xforce.ibmcloud.com/vulnerabilities/25249 • CWE-399: Resource Management Errors •