Filtered by vendor Absolute
Subscribe
Total
56 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-33444 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 3.7 LOW |
| CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server. | |||||
| CVE-2026-33445 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 5.9 MEDIUM |
| CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. | |||||
| CVE-2026-55398 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 3.7 LOW |
| CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server. | |||||
| CVE-2026-55399 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 4.3 MEDIUM |
| CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher. | |||||
| CVE-2026-40958 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 3.7 LOW |
| CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | |||||
| CVE-2026-40957 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 7.5 HIGH |
| o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator. | |||||
| CVE-2026-40956 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 3.7 LOW |
| CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak. | |||||
| CVE-2026-40955 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 3.7 LOW |
| CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | |||||
| CVE-2026-40954 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 3.7 LOW |
| CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client | |||||
| CVE-2026-40953 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 4.4 MEDIUM |
| CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control. | |||||
| CVE-2026-40952 | 2 Absolute, Microsoft | 2 Secure Access, Windows | 2026-07-16 | N/A | 7.8 HIGH |
| CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location. | |||||
| CVE-2026-33443 | 1 Absolute | 1 Secure Access | 2026-07-16 | N/A | 5.9 MEDIUM |
| CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. | |||||
| CVE-2026-40951 | 2 Absolute, Microsoft | 2 Secure Access, Windows | 2026-06-17 | N/A | 5.5 MEDIUM |
| CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service. | |||||
| CVE-2026-40950 | 1 Absolute | 1 Secure Access | 2026-06-17 | N/A | 6.5 MEDIUM |
| CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service | |||||
| CVE-2026-40949 | 2 Absolute, Microsoft | 2 Secure Access, Windows | 2026-06-17 | N/A | 4.4 MEDIUM |
| CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. | |||||
| CVE-2026-33452 | 2 Absolute, Microsoft | 2 Secure Access, Windows | 2026-06-17 | N/A | 5.5 MEDIUM |
| CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system. | |||||
| CVE-2026-33451 | 2 Absolute, Microsoft | 2 Secure Access, Windows | 2026-06-17 | N/A | 7.8 HIGH |
| CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system. | |||||
| CVE-2026-33450 | 2 Absolute, Apple | 2 Secure Access, Macos | 2026-06-17 | N/A | 5.5 MEDIUM |
| CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service. | |||||
| CVE-2026-33449 | 1 Absolute | 1 Secure Access | 2026-06-17 | N/A | 7.5 HIGH |
| CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, overwriting a small portion of memory conceivably leading to a denial of service. | |||||
| CVE-2026-33448 | 2 Absolute, Apple | 2 Secure Access, Macos | 2026-06-17 | N/A | 3.3 LOW |
| CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets. | |||||
