VYPR
Vendor

Revenera

Products
17
CVEs
36
Across products
44
Status
Private

Products

17

Recent CVEs

36
View all 36 CVEs →
  • CVE-2015-8277CriFeb 24, 2016
    risk 0.66cvss 9.8epss 0.29

    Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a.

  • CVE-2020-12083CriSep 17, 2021
    risk 0.64cvss 9.9epss 0.01

    An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).

  • CVE-2018-20033CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.04

    A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat…

  • CVE-2017-6885CriMay 16, 2017
    risk 0.64cvss 9.8epss 0.01

    An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated privileges.

  • CVE-2026-4026HigJun 19, 2026
    risk 0.57cvss epss 0.00

    A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level.

  • CVE-2023-29080HigJan 30, 2025
    risk 0.55cvss epss 0.00

    Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The…

  • CVE-2024-2658HigJan 30, 2025
    risk 0.55cvss epss 0.01

    A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and…

  • CVE-2021-41526HigMar 29, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.

  • CVE-2017-6894HigMar 29, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the…

  • CVE-2016-10395HigJun 15, 2017
    risk 0.51cvss 7.8epss 0.00

    In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and…

  • CVE-2016-4560HigJul 2, 2016
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Flexera InstallAnywhere allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.

  • CVE-2016-2542HigFeb 24, 2016
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.

  • CVE-2019-8963HigMar 29, 2023
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.

  • CVE-2020-12080HigSep 17, 2021
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.

  • CVE-2020-12081HigJul 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system.

  • CVE-2019-8961HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can…

  • CVE-2019-8960HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a…

  • CVE-2018-20034HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.03

    A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between…

  • CVE-2018-20032HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd…

  • CVE-2018-20031HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between…