ISS maintains a line of host-based and network security products, including the BlackICE and RealSecure families, that target endpoint protection and intrusion detection across enterprise environments. The vendor's vulnerability disclosures, while modest in count, concentrate around input-validation and permission-assignment weaknesses typical of security software that processes untrusted network traffic and manages system access controls. Notably, this vendor's vulnerabilities frequently acquire public exploit code, reflecting the appeal of security tools as targets for attackers seeking to disable or bypass protection mechanisms. Defenders should prioritize patching these products given their critical role in the security stack, as compromise of the protection layer itself can amplify downstream risk; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iss over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0362HIGH Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE produc | Apr 15, 2004 | 7.5 | 76 | NO | YES |
CVE-2002-0480HIGH ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connec | Aug 12, 2002 | 10.0 | 31 | NO | NO |
CVE-2001-0669HIGH Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, ( | Oct 30, 2001 | 7.5 | 29 | NO | YES |
CVE-2004-1714HIGH BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows loca | Aug 11, 2004 | 7.1 | 27 | NO | YES |
CVE-2004-0193HIGH Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, Rea | Mar 15, 2004 | 7.5 | 22 | NO | NO |
CVE-2002-0237HIGH Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service | May 29, 2002 | 7.5 | 22 | NO | NO |
CVE-2006-4541MEDIUM RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOp | Sep 5, 2006 | 4.6 | 21 | NO | YES |
CVE-2007-2690HIGH Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allo | May 16, 2007 | 7.8 | 20 | NO | NO |
CVE-2002-1122HIGH Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web | Sep 24, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-0956HIGH BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions. | Oct 4, 2002 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iss.
Media articles that mention a CVE ID that affects a product developed by Iss — matched by CVE ID, not by vendor name.