Vulnerabilities > Mandiant

DATE CVE VULNERABILITY TITLE RISK
2006-12-20 CVE-2006-6477 Denial of Service and Agent Hijacking vulnerability in Mandiant First Response
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent by hijacking an HTTP FRAgent daemon and conducting a man-in-the-middle (MITM) attack.
local
high complexity
mandiant
2.4
2006-12-20 CVE-2006-6476 Denial of Service and Agent Hijacking vulnerability in Mandiant First Response
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a denial of service (loss of daemon operation).
local
high complexity
mandiant
2.4
2006-12-20 CVE-2006-6475 Denial of Service and Agent Hijacking vulnerability in Mandiant First Response
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode with SSL enabled, allows remote attackers to cause a denial of service (refused connections) via malformed requests, which results in a mishandled exception.
network
mandiant
7.1