Vulnerabilities > Macrovision > Update Service

DATE CVE VULNERABILITY TITLE RISK
2008-01-04 CVE-2007-6654 Buffer Errors vulnerability in Macrovision Update Service 5.1.10047363
Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660.
network
macrovision CWE-119
critical
9.3
2007-11-02 CVE-2007-5660 Remote Code Execution vulnerability in Macrovision InstallShield Update Service Isusweb.DLL
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
network
macrovision
critical
9.3
2007-06-06 CVE-2007-2419 Unspecified vulnerability in Macrovision Flexnet Connect and Update Service
Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.
network
low complexity
macrovision
critical
10.0
2007-06-01 CVE-2007-0328 Unspecified vulnerability in Macrovision Flexnet Connect and Update Service
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
network
macrovision
critical
9.3