Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Iss

First CVE: Feb 20, 1999Active for: 27 yearsTotal CVEs: 24
40.3
VTI Score
Medium

ISS maintains a line of host-based and network security products, including the BlackICE and RealSecure families, that target endpoint protection and intrusion detection across enterprise environments. The vendor's vulnerability disclosures, while modest in count, concentrate around input-validation and permission-assignment weaknesses typical of security software that processes untrusted network traffic and manages system access controls. Notably, this vendor's vulnerabilities frequently acquire public exploit code, reflecting the appeal of security tools as targets for attackers seeking to disable or bypass protection mechanisms. Defenders should prioritize patching these products given their critical role in the security stack, as compromise of the protection layer itself can amplify downstream risk; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Iss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 20, 1999
27 years ago
Most Recent CVE
Oct 21, 2014
4,294 days ago

Products(22 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0362HIGH
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE produc
Apr 15, 20047.576NOYES
CVE-2002-0480HIGH
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connec
Aug 12, 200210.031NONO
CVE-2001-0669HIGH
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (
Oct 30, 20017.529NOYES
CVE-2004-1714HIGH
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows loca
Aug 11, 20047.127NOYES
CVE-2004-0193HIGH
Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, Rea
Mar 15, 20047.522NONO
CVE-2002-0237HIGH
Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service
May 29, 20027.522NONO
CVE-2006-4541MEDIUM
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOp
Sep 5, 20064.621NOYES
CVE-2007-2690HIGH
Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode character encodings, which might allo
May 16, 20077.820NONO
CVE-2002-1122HIGH
Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web
Sep 24, 20027.520NONO
CVE-2002-0956HIGH
BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions.
Oct 4, 20027.519NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
46%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.2%)
Network0 (0.0%)
Unknown23 (95.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.2%)
High0 (0.0%)
Unknown23 (95.8%)
User Interaction
None1 (4.2%)
Unknown23 (95.8%)
Required0 (0.0%)
Privileges Required
Low1 (4.2%)
High0 (0.0%)
None0 (0.0%)
Unknown23 (95.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
20.8% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Iss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Iss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Iss's Products

View all 2 CNAs →

Top CWEs