Show filters
146 Total Results
Displaying 51-60 of 146
Sort by:
Attacker Value
Unknown
CVE-2022-32137
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.
0
Attacker Value
Unknown
CVE-2022-32136
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninitialized pointer, resulting in a denial-of-service. User interaction is not required.
0
Attacker Value
Unknown
CVE-2022-1965
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.
0
Attacker Value
Unknown
CVE-2022-32143
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required
0
Attacker Value
Unknown
CVE-2022-32142
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which can lead to a change of local files. User interaction is not required.
0
Attacker Value
Unknown
CVE-2022-32141
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
0
Attacker Value
Unknown
CVE-2022-32139
Disclosure Date: June 15, 2022 (last updated February 24, 2025)
In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, resulting in a denial-of-service condition. User Interaction is not required.
0
Attacker Value
Unknown
CVE-2021-41662
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.
0
Attacker Value
Unknown
CVE-2022-22975
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or AD server to include special characters, which could be used to perform LDAP query injection on the Supervisor's LDAP query which determines their Kubernetes group membership.
0
Attacker Value
Unknown
CVE-2022-27658
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
0