Flexera Flexnet Publisher vulnerabilities
10 known vulnerabilities affecting flexera/flexnet_publisher.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9
Vulnerabilities
Page 1 of 1
CVE-2024-2658HIGHCVSS 8.5fixed in 2024 R1 (11.19.6.0)2025-01-30
CVE-2024-2658 [HIGH] CWE-427 CVE-2024-2658: A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a maliciou
cvelistv5nvd
CVE-2019-8963HIGHCVSS 7.5v11.16.52023-03-29
CVE-2019-8963 [HIGH] CVE-2019-8963: A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when
A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.
nvd
CVE-2020-12080HIGHCVSS 7.5v11.16.62021-09-17
CVE-2020-12080 [HIGH] CWE-20 CVE-2020-12080: A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.
A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.
nvd
CVE-2020-12081HIGHCVSS 7.5v11.14.0.22020-07-31
CVE-2020-12081 [HIGH] CVE-2020-12081: An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0
An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system.
nvd
CVE-2019-8961HIGHCVSS 7.5v11.16.22020-04-21
CVE-2019-8961 [HIGH] CWE-674 CVE-2019-8961: A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publish
A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to cause a stack exhaustion condition.
nvd
CVE-2019-8960HIGHCVSS 7.5v11.16.22020-04-21
CVE-2019-8960 [HIGH] CWE-754 CVE-2019-8960: A Denial of Service vulnerability related to command handling has been identified in FlexNet Publish
A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the f
nvd
CVE-2018-20034HIGHCVSS 7.5≤ 11.16.1.02019-03-21
CVE-2018-20034 [HIGH] CVE-2018-20034: A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon com
A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
nvd
CVE-2018-20032HIGHCVSS 7.5≤ 11.16.1.02019-03-21
CVE-2018-20032 [HIGH] CVE-2018-20032: A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components
A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
nvd
CVE-2018-20031HIGHCVSS 7.5≤ 11.16.1.02019-03-21
CVE-2018-20031 [HIGH] CVE-2018-20031: A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon com
A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.
nvd
CVE-2018-20033CRITICALCVSS 9.8≤ 11.16.1.02019-02-25
CVE-2018-20033 [CRITICAL] CWE-770 CVE-2018-20033: A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher ver
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor
nvd