Flexnet Publisher
Vendor:
First CVE: Jan 19, 2012 · Active for 14 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 79% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Flexnet Publisher over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 19, 2012
14 years ago
Most Recent CVE
Jun 15, 2017
3,330 days ago
CVE Severity & Scoring
Flexnet Publisher5 CVEs
20%
60%
20%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (20.0%)
Network2 (40.0%)
Unknown2 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High0 (0.0%)
Unknown2 (40.0%)
User Interaction
None2 (40.0%)
Unknown2 (40.0%)
Required1 (20.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None2 (40.0%)
Unknown2 (40.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4135HIGH Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allow remote attackers to execute arbitrary code via v | Jan 19, 2012 | 10.0 | 58 | NO | YES |
CVE-2015-8277CRITICAL Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a | Feb 24, 2016 | 9.8 | 41 | NO | NO |
CVE-2011-4134HIGH Heap-based buffer overflow in lmadmin in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Manager) allows remote attackers to execute arbitrary code via a crafted 0x2f p | Jan 19, 2012 | 10.0 | 30 | NO | NO |
CVE-2016-10395HIGH In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the Flex | Jun 15, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-5571MEDIUM Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and t | Mar 3, 2017 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
20.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Flexnet Publisher
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.10 | 2 | 10.0 | 18.4% | 0 | 1 |