Total
11483 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-0145 | 1 Vercot | 1 Serva32 | 2013-05-22 | 5.0 MEDIUM | N/A |
Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request. | |||||
CVE-2012-5409 | 1 Siemens | 1 Sipass Integrated | 2013-05-20 | 10.0 HIGH | N/A |
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack. | |||||
CVE-2012-4708 | 1 3s-software | 1 Codesys Gateway-server | 2013-05-20 | 10.0 HIGH | N/A |
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | |||||
CVE-2012-4711 | 1 Wellintech | 1 Kingview | 2013-05-20 | 10.0 HIGH | N/A |
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet. | |||||
CVE-2012-3792 | 1 Pro-face | 2 Pro-server Ex, Wingp Pc Runtime | 2013-05-20 | 5.0 MEDIUM | N/A |
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via a crafted packet that triggers a certain Find Node check attempt. | |||||
CVE-2012-3795 | 1 Pro-face | 2 Pro-server Ex, Wingp Pc Runtime | 2013-05-20 | 5.0 MEDIUM | N/A |
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode and a large value in a size field. | |||||
CVE-2012-3797 | 1 Pro-face | 2 Pro-server Ex, Wingp Pc Runtime | 2013-05-20 | 10.0 HIGH | N/A |
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode. | |||||
CVE-2011-5007 | 1 3ssoftware | 1 Codesys | 2013-05-20 | 10.0 HIGH | N/A |
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080. | |||||
CVE-2011-1918 | 1 Ge | 1 Intelligent Platforms Proficy Historian | 2013-05-20 | 10.0 HIGH | N/A |
Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic. | |||||
CVE-2011-0340 | 2 Advantech, Indusoft | 3 Advantech Studio, Thin Client, Web Studio | 2013-05-20 | 9.3 HIGH | N/A |
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method. | |||||
CVE-2011-0342 | 1 Indusoft | 1 Web Studio | 2013-05-20 | 10.0 HIGH | N/A |
Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute arbitrary code via a long parameter to the (1) Open, (2) Close, or (3) SetCurrentLanguage method. | |||||
CVE-2013-1346 | 1 Microsoft | 1 Malware Protection Engine | 2013-05-15 | 9.3 HIGH | N/A |
mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file. | |||||
CVE-2013-3075 | 2 Mitsubishi-automation, Schneider-electric | 3 Mitsubishi Mx Component, Citectfacilities, Citectscada | 2013-05-14 | 10.0 HIGH | N/A |
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle property value to a certain ActiveX control. | |||||
CVE-2013-1664 | 1 Openstack | 6 Cinder Folsom, Compute \(nova\) Essex, Compute \(nova\) Folsom and 3 more | 2013-05-14 | 5.0 MEDIUM | N/A |
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. | |||||
CVE-2013-0728 | 1 Hexagon | 1 Erdas Apollo Ecwp | 2013-05-05 | 10.0 HIGH | N/A |
Multiple stack-based buffer overflows in NCSAddOn.dll in the ERDAS APOLLO ECWP plugin before 13.00.0001 for Internet Explorer, Firefox, and Chrome allow remote attackers to execute arbitrary code via a long property value. | |||||
CVE-2013-0726 | 1 Hexagon | 1 Erdas Er Viewer | 2013-05-05 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code via a crafted pathname in an ERS file. | |||||
CVE-2013-0635 | 1 Adobe | 1 Shockwave Player | 2013-05-03 | 10.0 HIGH | N/A |
Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |||||
CVE-2013-0636 | 1 Adobe | 1 Shockwave Player | 2013-05-03 | 10.0 HIGH | N/A |
Stack-based buffer overflow in Adobe Shockwave Player before 12.0.0.112 allows attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2012-3936 | 1 Cisco | 1 Webex Recording Format Player | 2013-05-03 | 9.3 HIGH | N/A |
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCua40962. | |||||
CVE-2012-3937 | 1 Cisco | 1 Webex Recording Format Player | 2013-05-03 | 9.3 HIGH | N/A |
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72967. |