Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Flexera Subscribe
Total 12 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-12083 1 Flexera 1 Flexnet Code Insight 2022-07-12 6.5 MEDIUM 9.9 CRITICAL
An elevated privileges issue related to Spring MVC calls impacts Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).
CVE-2018-20033 2 Flexera, Oracle 2 Flexnet Publisher, Communications Lsms 2022-04-18 7.5 HIGH 9.8 CRITICAL
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.
CVE-2018-20031 2 Flexera, Oracle 2 Flexnet Publisher, Communications Lsms 2022-04-11 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
CVE-2018-20034 2 Flexera, Oracle 2 Flexnet Publisher, Communications Lsms 2022-04-11 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
CVE-2018-20032 2 Flexera, Oracle 2 Flexnet Publisher, Communications Lsms 2022-04-11 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
CVE-2020-12080 1 Flexera 1 Flexnet Publisher 2022-04-01 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.
CVE-2021-41525 1 Flexera 1 Flexnet Inventory Agent And Beacon 2021-10-04 2.1 LOW 5.5 MEDIUM
An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior.
CVE-2020-12082 1 Flexera 1 Flexnet Code Insight 2021-09-28 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting issue impacts certain areas of the Web UI for Code Insight v7.x releases up to and including 2020 R1 (7.11.0-64).
CVE-2020-12081 1 Flexera 1 Flexnet Publisher 2021-07-21 5.0 MEDIUM 7.5 HIGH
An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system.
CVE-2019-8961 1 Flexera 1 Flexnet Publisher 2021-07-21 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to cause a stack exhaustion condition.
CVE-2016-2542 1 Flexera 1 Installshield 2021-06-14 7.2 HIGH 7.8 HIGH
Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.
CVE-2019-8960 1 Flexera 1 Flexnet Publisher 2020-04-28 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the function eventually return an unexpected value which leads to an exception being thrown. The end result can be process termination.