Show filters
649 Total Results
Displaying 151-160 of 649
Sort by:
Attacker Value
Unknown

CVE-2021-41057

Disclosure Date: November 14, 2021 (last updated February 23, 2025)
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
Attacker Value
Unknown

CVE-2021-34596

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
Attacker Value
Unknown

CVE-2021-34595

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
Attacker Value
Unknown

CVE-2021-34593

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
0
Attacker Value
Unknown

CVE-2021-40142

Disclosure Date: August 27, 2021 (last updated February 23, 2025)
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Attacker Value
Unknown

CVE-2021-35940

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
Attacker Value
Unknown

CVE-2021-3642

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Attacker Value
Unknown

CVE-2021-33486

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
Attacker Value
Unknown

CVE-2021-33485

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
Attacker Value
Unknown

CVE-2021-36763

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.