ISS records
24 published records for vendor iss.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4.2%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-399 Resource Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2004-0362Weaponized | Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various Reiss · blackice agent server | High7.5 | — | 73.3% | Apr 15, 2004 |
41Plan | CVE-2002-0480No exploit | ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become aiss · realsecure nokia | Critical10.0 | — | 2.6% | Aug 12, 2002 |
32Monitor | CVE-2004-0193No exploit | Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensoiss · blackice agent server | High7.5 | — | 8.0% | Mar 15, 2004 |
32Monitor | CVE-2007-2690No exploit | Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicoiss · proventia a series xpu | High7.8 | — | 2.0% | May 15, 2007 |
31Monitor | CVE-2001-0669Proof of concept | Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detectioncisco · catalyst 6000 intrusion detection system module | High7.5 | — | 4.4% | Oct 30, 2001 |
31Monitor | CVE-2002-0237No exploit | Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remotiss · blackice agent | High7.5 | — | 3.7% | May 29, 2002 |
31Monitor | CVE-2002-1122No exploit | Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers tiss · internet scanner | High7.5 | — | 3.2% | Sep 24, 2002 |
30Monitor | CVE-2002-0956No exploit | BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass inteniss · blackice agent | High7.5 | — | 1.5% | Oct 4, 2002 |
30Monitor | CVE-2000-0562No exploit | BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security settingiss · blackice agent | High7.5 | — | 1.3% | Jun 22, 2000 |
28Monitor | CVE-2004-1714Proof of concept | BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Fuliss · blackice pc protection · CWE-732 | High7.1 | — | 0.9% | Aug 11, 2004 |
28Monitor | CVE-1999-1168No exploit | install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of iss · internet security scanner | High7.2 | — | 0.5% | Feb 20, 1999 |
28Monitor | CVE-2005-2711No exploit | ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktopiss · blackice agent server | High7.2 | — | 0.4% | Dec 31, 2005 |
21Monitor | CVE-2003-0702No exploit | Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remoteiss · realsecure server sensor | Medium5.0 | — | 2.8% | Oct 20, 2003 |
21Monitor | CVE-2006-3840No exploit | The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Seiss · blackice pc protection · CWE-399 | Medium5.0 | — | 2.4% | Jul 27, 2006 |
21Monitor | CVE-2014-7725No exploit | The Rally Albania Live 2014 (aka com.wRallyAlbaniaLIVE2014) application 0.11 for Android does not verify X.509 certificates from SSL serversiss · rally albania live 2014 · CWE-310 | Medium5.4 | — | 0.3% | Oct 21, 2014 |
20Monitor | CVE-2000-0692No exploit | ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.iss · realsecure | Medium5.0 | — | 1.4% | Oct 20, 2000 |
20Monitor | CVE-2002-0957No exploit | The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers toiss · blackice agent | Medium5.0 | — | 1.3% | Oct 4, 2002 |
20Monitor | CVE-2002-1280No exploit | Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).iss · realsecure event collector | Medium5.0 | — | 1.0% | May 17, 2002 |
18Monitor | CVE-2006-4541Proof of concept | RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crasiss · blackice pc protection · CWE-20 | Medium4.6 | — | 0.7% | Sep 5, 2006 |
18Monitor | CVE-2004-2126No exploit | The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, iss · blackice pc protection | Medium4.6 | — | 0.4% | Dec 31, 2004 |
18Monitor | CVE-2004-2125No exploit | Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows locaiss · blackice agent server | Medium4.6 | — | 0.4% | Dec 31, 2004 |
18Monitor | CVE-2006-3999No exploit | ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll Blaciss · blackice pc protection | Medium4.6 | — | 0.3% | Aug 4, 2006 |
17Monitor | CVE-2003-1527No exploit | BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IPibm · internet security systems blackice defender | Medium4.3 | — | 1.4% | Dec 31, 2003 |
8Monitor | CVE-2006-7129Proof of concept | ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the Ziss · blackice pc protection | Low2.1 | — | 0.8% | Mar 5, 2007 |
- CVE-2004-036252Plan
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various Re
HighCVSS 7.5WeaponizedEPSS 73%iss · blackice agent serverApr 15, 2004
- CVE-2002-048041Plan
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a
CriticalCVSS 10.0No exploitEPSS 3%iss · realsecure nokiaAug 12, 2002
- CVE-2004-019332Monitor
Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Senso
HighCVSS 7.5No exploitEPSS 8%iss · blackice agent serverMar 15, 2004
- CVE-2007-269032Monitor
Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unico
HighCVSS 7.8No exploitEPSS 2%iss · proventia a series xpuMay 15, 2007
- CVE-2001-066931Monitor
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection
HighCVSS 7.5Proof of conceptEPSS 4%cisco · catalyst 6000 intrusion detection system moduleOct 30, 2001
- CVE-2002-023731Monitor
Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remot
HighCVSS 7.5No exploitEPSS 4%iss · blackice agentMay 29, 2002
- CVE-2002-112231Monitor
Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers t
HighCVSS 7.5No exploitEPSS 3%iss · internet scannerSep 24, 2002
- CVE-2002-095630Monitor
BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass inten
HighCVSS 7.5No exploitEPSS 1%iss · blackice agentOct 4, 2002
- CVE-2000-056230Monitor
BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting
HighCVSS 7.5No exploitEPSS 1%iss · blackice agentJun 22, 2000
- CVE-2004-171428Monitor
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Ful
HighCVSS 7.1Proof of conceptEPSS 1%iss · blackice pc protectionAug 11, 2004
- CVE-1999-116828Monitor
install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of
HighCVSS 7.2No exploitEPSS 1%iss · internet security scannerFeb 20, 1999
- CVE-2005-271128Monitor
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop
HighCVSS 7.2No exploitEPSS 0%iss · blackice agent serverDec 31, 2005
- CVE-2003-070221Monitor
Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote
MediumCVSS 5.0No exploitEPSS 3%iss · realsecure server sensorOct 20, 2003
- CVE-2006-384021Monitor
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Se
MediumCVSS 5.0No exploitEPSS 2%iss · blackice pc protectionJul 27, 2006
- CVE-2014-772521Monitor
The Rally Albania Live 2014 (aka com.wRallyAlbaniaLIVE2014) application 0.11 for Android does not verify X.509 certificates from SSL servers
MediumCVSS 5.4No exploitEPSS 0%iss · rally albania live 2014Oct 21, 2014
- CVE-2000-069220Monitor
ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.
MediumCVSS 5.0No exploitEPSS 1%iss · realsecureOct 20, 2000
- CVE-2002-095720Monitor
The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to
MediumCVSS 5.0No exploitEPSS 1%iss · blackice agentOct 4, 2002
- CVE-2002-128020Monitor
Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).
MediumCVSS 5.0No exploitEPSS 1%iss · realsecure event collectorMay 17, 2002
- CVE-2006-454118Monitor
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (cras
MediumCVSS 4.6Proof of conceptEPSS 1%iss · blackice pc protectionSep 5, 2006
- CVE-2004-212618Monitor
The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini,
MediumCVSS 4.6No exploitEPSS 0%iss · blackice pc protectionDec 31, 2004
- CVE-2004-212518Monitor
Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows loca
MediumCVSS 4.6No exploitEPSS 0%iss · blackice agent serverDec 31, 2004
- CVE-2006-399918Monitor
ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll Blac
MediumCVSS 4.6No exploitEPSS 0%iss · blackice pc protectionAug 4, 2006
- CVE-2003-152717Monitor
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP
MediumCVSS 4.3No exploitEPSS 1%ibm · internet security systems blackice defenderDec 31, 2003
- CVE-2006-71298Monitor
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the Z
LowCVSS 2.1Proof of conceptEPSS 1%iss · blackice pc protectionMar 5, 2007