VYPR

Blackice Agent Server

by Iss

CVEs (8)

  • CVE-2004-0362Apr 15, 2004
    risk 0.09cvss epss 0.73

    Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a…

  • CVE-2004-0193Mar 15, 2004
    risk 0.01cvss epss 0.08

    Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection…

  • CVE-2005-2711Dec 31, 2005
    risk 0.00cvss epss 0.00

    ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which…

  • CVE-2004-2125Dec 31, 2004
    risk 0.00cvss epss 0.00

    Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.

  • CVE-2002-0956Oct 4, 2002
    risk 0.00cvss epss 0.01

    BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions.

  • CVE-2002-0957Oct 4, 2002
    risk 0.00cvss epss 0.01

    The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than…

  • CVE-2002-0237May 29, 2002
    risk 0.00cvss epss 0.04

    Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping packets.

  • CVE-2000-0562Jun 22, 2000
    risk 0.00cvss epss 0.01

    BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.