Show filters
325 Total Results
Displaying 131-140 of 325
Sort by:
Attacker Value
Unknown

CVE-2020-25157

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
Attacker Value
Unknown

CVE-2020-16202

Disclosure Date: September 22, 2020 (last updated February 22, 2025)
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges.
Attacker Value
Unknown

CVE-2020-16245

Disclosure Date: August 25, 2020 (last updated February 22, 2025)
Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.
Attacker Value
Unknown

CVE-2020-16229

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Attacker Value
Unknown

CVE-2020-16217

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Attacker Value
Unknown

CVE-2020-16215

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Attacker Value
Unknown

CVE-2020-16213

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Attacker Value
Unknown

CVE-2020-16211

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.
Attacker Value
Unknown

CVE-2020-16207

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
Attacker Value
Unknown

CVE-2020-14499

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.