Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
High
CVE-2014-0160 (AKA: Heartbleed)
Disclosure Date: April 07, 2014 (last updated July 03, 2024)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
0
Attacker Value
Unknown
CVE-2014-4684
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
0
Attacker Value
Unknown
CVE-2014-4685
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
0
Attacker Value
Unknown
CVE-2014-4683
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.
0
Attacker Value
Unknown
CVE-2014-4682
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
0
Attacker Value
Unknown
CVE-2014-4686
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.
0
Attacker Value
Unknown
CVE-2013-0679
Disclosure Date: March 21, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving a query for a pathname.
0
Attacker Value
Unknown
CVE-2013-0676
Disclosure Date: March 21, 2013 (last updated October 05, 2023)
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to obtain sensitive information via a SQL query.
0
Attacker Value
Unknown
CVE-2013-0675
Disclosure Date: March 21, 2013 (last updated October 05, 2023)
Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-0674
Disclosure Date: March 21, 2013 (last updated October 05, 2023)
Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter.
0