Skip to content
Noroxi

ISS records

24 published records for vendor iss.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 4.2%
Pre-auth RCE
5
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

24 records
  • Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various Re

    HighCVSS 7.5WeaponizedEPSS 73%

    iss · blackice agent serverApr 15, 2004

  • ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a

    CriticalCVSS 10.0No exploitEPSS 3%

    iss · realsecure nokiaAug 12, 2002

  • CVE-2004-0193
    32Monitor

    Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Senso

    HighCVSS 7.5No exploitEPSS 8%

    iss · blackice agent serverMar 15, 2004

  • CVE-2007-2690
    32Monitor

    Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unico

    HighCVSS 7.8No exploitEPSS 2%

    iss · proventia a series xpuMay 15, 2007

  • CVE-2001-0669
    31Monitor

    Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection

    HighCVSS 7.5Proof of conceptEPSS 4%

    cisco · catalyst 6000 intrusion detection system moduleOct 30, 2001

  • CVE-2002-0237
    31Monitor

    Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remot

    HighCVSS 7.5No exploitEPSS 4%

    iss · blackice agentMay 29, 2002

  • CVE-2002-1122
    31Monitor

    Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers t

    HighCVSS 7.5No exploitEPSS 3%

    iss · internet scannerSep 24, 2002

  • CVE-2002-0956
    30Monitor

    BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass inten

    HighCVSS 7.5No exploitEPSS 1%

    iss · blackice agentOct 4, 2002

  • CVE-2000-0562
    30Monitor

    BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting

    HighCVSS 7.5No exploitEPSS 1%

    iss · blackice agentJun 22, 2000

  • CVE-2004-1714
    28Monitor

    BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Ful

    HighCVSS 7.1Proof of conceptEPSS 1%

    iss · blackice pc protectionAug 11, 2004

  • CVE-1999-1168
    28Monitor

    install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of

    HighCVSS 7.2No exploitEPSS 1%

    iss · internet security scannerFeb 20, 1999

  • CVE-2005-2711
    28Monitor

    ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop

    HighCVSS 7.2No exploitEPSS 0%

    iss · blackice agent serverDec 31, 2005

  • CVE-2003-0702
    21Monitor

    Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote

    MediumCVSS 5.0No exploitEPSS 3%

    iss · realsecure server sensorOct 20, 2003

  • CVE-2006-3840
    21Monitor

    The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Se

    MediumCVSS 5.0No exploitEPSS 2%

    iss · blackice pc protectionJul 27, 2006

  • CVE-2014-7725
    21Monitor

    The Rally Albania Live 2014 (aka com.wRallyAlbaniaLIVE2014) application 0.11 for Android does not verify X.509 certificates from SSL servers

    MediumCVSS 5.4No exploitEPSS 0%

    iss · rally albania live 2014Oct 21, 2014

  • CVE-2000-0692
    20Monitor

    ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.

    MediumCVSS 5.0No exploitEPSS 1%

    iss · realsecureOct 20, 2000

  • CVE-2002-0957
    20Monitor

    The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to

    MediumCVSS 5.0No exploitEPSS 1%

    iss · blackice agentOct 4, 2002

  • CVE-2002-1280
    20Monitor

    Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).

    MediumCVSS 5.0No exploitEPSS 1%

    iss · realsecure event collectorMay 17, 2002

  • CVE-2006-4541
    18Monitor

    RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (cras

    MediumCVSS 4.6Proof of conceptEPSS 1%

    iss · blackice pc protectionSep 5, 2006

  • CVE-2004-2126
    18Monitor

    The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini,

    MediumCVSS 4.6No exploitEPSS 0%

    iss · blackice pc protectionDec 31, 2004

  • CVE-2004-2125
    18Monitor

    Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows loca

    MediumCVSS 4.6No exploitEPSS 0%

    iss · blackice agent serverDec 31, 2004

  • CVE-2006-3999
    18Monitor

    ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll Blac

    MediumCVSS 4.6No exploitEPSS 0%

    iss · blackice pc protectionAug 4, 2006

  • CVE-2003-1527
    17Monitor

    BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP

    MediumCVSS 4.3No exploitEPSS 1%

    ibm · internet security systems blackice defenderDec 31, 2003

  • ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the Z

    LowCVSS 2.1Proof of conceptEPSS 1%

    iss · blackice pc protectionMar 5, 2007