flexera CVE Vulnerabilities & Metrics

Focus on flexera vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About flexera Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with flexera. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total flexera CVEs: 14
Earliest CVE date: 24 Feb 2016, 03:59 UTC
Latest CVE date: 26 Jan 2024, 20:15 UTC

Latest CVE reference: CVE-2023-29081

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical flexera CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.7

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 7
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS flexera CVEs

These are the five CVEs with the highest CVSS scores for flexera, sorted by severity first and recency.

All CVEs for flexera

CVE-2023-29081 flexera vulnerability CVSS: 0 26 Jan 2024, 20:15 UTC

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.

CVE-2021-41526 flexera vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.

CVE-2019-8963 flexera vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.

CVE-2017-6894 flexera vulnerability CVSS: 0 29 Mar 2023, 21:15 UTC

A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.

CVE-2021-41525 flexera vulnerability CVSS: 2.1 21 Sep 2021, 15:15 UTC

An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior.

CVE-2020-12080 flexera vulnerability CVSS: 5.0 17 Sep 2021, 18:15 UTC

A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash.

CVE-2020-12081 flexera vulnerability CVSS: 5.0 31 Jul 2020, 17:15 UTC

An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system.

CVE-2019-8961 flexera vulnerability CVSS: 5.0 21 Apr 2020, 15:15 UTC

A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to cause a stack exhaustion condition.

CVE-2019-8960 flexera vulnerability CVSS: 5.0 21 Apr 2020, 15:15 UTC

A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the function eventually return an unexpected value which leads to an exception being thrown. The end result can be process termination.

CVE-2018-20034 flexera vulnerability CVSS: 5.0 21 Mar 2019, 21:29 UTC

A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

CVE-2018-20032 flexera vulnerability CVSS: 5.0 21 Mar 2019, 21:29 UTC

A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

CVE-2018-20031 flexera vulnerability CVSS: 5.0 21 Mar 2019, 21:29 UTC

A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

CVE-2018-20033 flexera vulnerability CVSS: 7.5 25 Feb 2019, 20:29 UTC

A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.

CVE-2016-2542 flexera vulnerability CVSS: 7.2 24 Feb 2016, 03:59 UTC

Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.