Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2021-33485

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Attacker Value
Unknown

CVE-2021-36763

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
Attacker Value
Unknown

CVE-2021-29242

Disclosure Date: May 03, 2021 (last updated February 22, 2025)
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Attacker Value
Unknown

CVE-2020-15806

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
Attacker Value
Unknown

CVE-2019-18858

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
Attacker Value
Unknown

CVE-2019-13548

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
Attacker Value
Unknown

CVE-2019-13532

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.