Vulnerabilities
Products Security index
Vulnerabilities
CVE-2016-20060
Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation
CVE-2020-17365
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
CVE-2020-12828
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
CVE-2011-0020
pango: Heap-based buffer overflow by rendering glyph box for certain FT_Bitmap objects
CVE-2009-1194
pango: pango_glyph_string_set_size integer overflow
