Vulnerabilities > Macrovision

DATE CVE VULNERABILITY TITLE RISK
2008-09-18 CVE-2008-2470 Buffer Overflow vulnerability in Macrovision Flexnet Connect 6.0
The InstallShield Update Service Agent ActiveX control in isusweb.dll allows remote attackers to cause a denial of service (memory corruption and browser crash) and possibly execute arbitrary code via a call to ExecuteRemote with a URL that results in a 404 error response.
network
macrovision
critical
9.3
2008-04-04 CVE-2007-5661 Code Injection vulnerability in Macrovision Installshield
The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.
network
macrovision CWE-94
critical
9.3
2008-01-04 CVE-2007-6654 Buffer Errors vulnerability in Macrovision Update Service 5.1.10047363
Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660.
network
macrovision CWE-119
critical
9.3
2007-11-02 CVE-2007-5660 Remote Code Execution vulnerability in Macrovision InstallShield Update Service Isusweb.DLL
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
network
macrovision
critical
9.3
2007-10-19 CVE-2007-5587 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Macrovision Safedisc
Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
6.9
2007-06-06 CVE-2007-2419 Unspecified vulnerability in Macrovision Flexnet Connect and Update Service
Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.
network
low complexity
macrovision
critical
10.0
2007-06-01 CVE-2007-0328 Unspecified vulnerability in Macrovision Flexnet Connect and Update Service
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
network
macrovision
critical
9.3
2007-04-19 CVE-2007-1009 Authentication Bypass vulnerability in Macrovision Installanywhere 8
Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.
local
low complexity
macrovision
4.6
2007-02-23 CVE-2007-0321 Unspecified vulnerability in Macrovision Flexnet Connect
Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method.
network
macrovision
critical
9.3
2007-02-23 CVE-2007-0320 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Macrovision Installfromtheweb
Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.
network
macrovision CWE-119
critical
9.3