Vulnerabilities > Macrovision > Flexnet Connect

DATE CVE VULNERABILITY TITLE RISK
2008-09-18 CVE-2008-2470 Buffer Overflow vulnerability in Macrovision Flexnet Connect 6.0
The InstallShield Update Service Agent ActiveX control in isusweb.dll allows remote attackers to cause a denial of service (memory corruption and browser crash) and possibly execute arbitrary code via a call to ExecuteRemote with a URL that results in a 404 error response.
network
macrovision
critical
9.3
2007-11-02 CVE-2007-5660 Remote Code Execution vulnerability in Macrovision InstallShield Update Service Isusweb.DLL
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
network
macrovision
critical
9.3
2007-06-06 CVE-2007-2419 Unspecified vulnerability in Macrovision Flexnet Connect and Update Service
Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.
network
low complexity
macrovision
critical
10.0
2007-06-01 CVE-2007-0328 Unspecified vulnerability in Macrovision Flexnet Connect and Update Service
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
network
macrovision
critical
9.3
2007-02-23 CVE-2007-0321 Unspecified vulnerability in Macrovision Flexnet Connect
Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method.
network
macrovision
critical
9.3