Show filters
401 Total Results
Displaying 261-270 of 401
Sort by:
Attacker Value
Unknown

CVE-2021-40872

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type cast, and must be restarted.
Attacker Value
Unknown

CVE-2021-40873

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
Attacker Value
Unknown

CVE-2021-42531

Disclosure Date: October 26, 2021 (last updated February 23, 2025)
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Attacker Value
Unknown

CVE-2021-42528

Disclosure Date: October 26, 2021 (last updated February 23, 2025)
XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2021-42530

Disclosure Date: October 26, 2021 (last updated February 23, 2025)
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
0
Attacker Value
Unknown

CVE-2021-42529

Disclosure Date: October 26, 2021 (last updated February 23, 2025)
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Attacker Value
Unknown

CVE-2021-42532

Disclosure Date: October 26, 2021 (last updated February 23, 2025)
XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
Attacker Value
Unknown

CVE-2021-34596

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
Attacker Value
Unknown

CVE-2021-34595

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
Attacker Value
Unknown

CVE-2021-34593

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
0