Welcome, Guest. Please login or register.
December 29, 2009, 04:17:08 AM

Login with username, password and session length

345920 Posts
38202 Topics
86777 Members

Latest Member: measurement

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Critikal
« previous next »
Pages: [1] Go Down Print
Author Topic: Critikal  (Read 985 times)
Frogster
Newbie
*
Offline Offline

Posts: 2


« on: September 13, 2007, 06:48:13 PM »

CVE-2007-1330   
Summary: Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.

Published: 3/7/2007

CVSS Severity: 4.4 (Medium)

CVE-2007-1051   
Summary: Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.17.183 and earlier uses a weak cryptographic hashing function (CRC32) to identify trusted modules, which allows local users to bypass security protections by substituting modified modules that have the same CRC32 value.

Published: 2/21/2007

CVSS Severity: 4.6 (Medium)

CVE-2007-0709   
Summary: cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.16.174 and earlier does not validate arguments that originate in user mode for the (1) NtCreateSection, (2) NtOpenProcess, (3) NtOpenSection, (4) NtOpenThread, and (5) NtSetValueKey hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.

Published: 2/3/2007

CVSS Severity: 7.2 (High)

CVE-2007-0708   
Summary: cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.

Published: 2/3/2007

CVSS Severity: 7.2 (High)

This is the org Text from   http://nvd.nist.gov/nvd.cfm?startrow=1
National Vulnerability Database

I use the Comodo Firewall for a long tome and i love it, because its one of the most secure PFW i know...(and i know many) i hope you will fix this probs

Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6254



« Reply #1 on: September 14, 2007, 12:20:46 PM »

That's old news reported by Matousec's results.  www.matousec.com

Comodo is well aware of it.  I think it may have already been addressed; I'm not sure about that, though.

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.043 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com