CVE-2015-7600
- EPSS 0.07%
- Veröffentlicht 06.10.2015 17:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.
CVE-2012-5429
- EPSS 0.11%
- Veröffentlicht 17.01.2013 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The VPN driver in Cisco VPN Client on Windows does not properly interact with the kernel, which allows local users to cause a denial of service (kernel fault and system crash) via a crafted application, aka Bug ID CSCuc81669.
CVE-2012-3052
- EPSS 0.14%
- Veröffentlicht 16.09.2012 10:34:50
- Zuletzt bearbeitet 11.04.2025 00:51:21
Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.
CVE-2011-2678
- EPSS 0.03%
- Veröffentlicht 07.07.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file with an arbitrary program, aka ...
CVE-2009-4118
- EPSS 0.28%
- Veröffentlicht 01.12.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of servi...
CVE-2008-0324
- EPSS 0.59%
- Veröffentlicht 17.01.2008 03:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.
CVE-2007-4415
- EPSS 0.05%
- Veröffentlicht 18.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.
CVE-2007-4414
- EPSS 0.06%
- Veröffentlicht 18.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.
CVE-2007-1467
- EPSS 0.56%
- Veröffentlicht 16.03.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express...
CVE-2006-2679
- EPSS 0.05%
- Veröffentlicht 31.05.2006 10:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows local authenticated, interactive users to gain pri...