Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2020-10659
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain.
0
Attacker Value
Unknown
CVE-2018-13252
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.
0
Attacker Value
Unknown
CVE-2007-4594
Disclosure Date: August 29, 2007 (last updated October 04, 2023)
Entrust Entelligence Security Provider (ESP) 8 does not properly validate certificates in certain circumstances involving (1) a chain that omits the root Certification Authority (CA) certificate, or an application that specifies disregarding (2) unknown revocation statuses during path validation or (3) certain errors in the certification path, which might allow context-dependent attackers to spoof certificate authentication. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2004-0369
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.
0
Attacker Value
Unknown
CVE-2002-0712
Disclosure Date: February 03, 2004 (last updated February 22, 2025)
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.
0
Attacker Value
Unknown
CVE-2001-0853
Disclosure Date: December 06, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.
0
Attacker Value
Unknown
CVE-2001-1024
Disclosure Date: July 27, 2001 (last updated February 22, 2025)
login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument.
0