Flexerasoftware's vulnerability profile concentrates on software licensing, installation, and deployment management tools such as FlexNet Publisher, FlexNet Manager Suite, InstallAnywhere, and InstallShield—a narrow but strategically important product set embedded across enterprise software distribution chains. Vulnerabilities affecting these products skew toward serious outcomes and frequently acquire public exploit code, recurring through memory-safety issues, sensitive information exposure, and path-traversal weaknesses that characterize system-level installer and licensing code. Defenders should treat this vendor's advisories as a patching priority for any organization deploying or distributing software at scale; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flexerasoftware over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4135HIGH Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via v | Jan 19, 2012 | 10.0 | 58 | NO | YES |
CVE-2015-8277CRITICAL Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a | Feb 24, 2016 | 9.8 | 41 | NO | NO |
CVE-2011-4134HIGH Heap-based buffer overflow in lmadmin in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allows remote attackers to execute arbitrary code via a crafted 0x2f p | Jan 19, 2012 | 10.0 | 30 | NO | NO |
CVE-2017-6885CRITICAL An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 20 | May 16, 2017 | 9.8 | 29 | NO | NO |
CVE-2016-10395HIGH In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the Flex | Jun 15, 2017 | 7.8 | 25 | NO | NO |
CVE-2016-4560HIGH Untrusted search path vulnerability in Flexera InstallAnywhere allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher exe | Jul 2, 2016 | 7.8 | 25 | NO | NO |
CVE-2017-5571MEDIUM Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and t | Mar 3, 2017 | 6.1 | 22 | NO | NO |
Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, whi | Jan 19, 2012 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flexerasoftware.
Media articles that mention a CVE ID that affects a product developed by Flexerasoftware — matched by CVE ID, not by vendor name.