Show filters
401 Total Results
Displaying 221-230 of 401
Sort by:
Attacker Value
Unknown

CVE-2022-22515

Disclosure Date: June 01, 2022 (last updated February 23, 2025)
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
0
Attacker Value
Unknown

CVE-2022-22518

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.
0
Attacker Value
Unknown

CVE-2022-22519

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
Attacker Value
Unknown

CVE-2022-22517

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
Attacker Value
Unknown

CVE-2022-22514

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
Attacker Value
Unknown

CVE-2022-22513

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
Attacker Value
Unknown

CVE-2022-21821

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.
0
Attacker Value
Unknown

CVE-2021-44663

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.
Attacker Value
Unknown

CVE-2021-44662

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Site Scripting (XSS) vulnerability exists in the Xerte Project Xerte through 3.8.4 via the link parameter in print.php.
Attacker Value
Unknown

CVE-2021-3948

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.