Show filters
211 Total Results
Displaying 61-70 of 211
Sort by:
Attacker Value
Unknown

CVE-2019-16900

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.
Attacker Value
Unknown

CVE-2019-16901

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.
Attacker Value
Unknown

CVE-2019-16899

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.
Attacker Value
Unknown

CVE-2019-13556

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.
Attacker Value
Unknown

CVE-2019-13558

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.
Attacker Value
Unknown

CVE-2019-13550

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensitive information, cause improper control of generation of code, which may allow remote code execution or cause a system crash.
Attacker Value
Unknown

CVE-2019-13552

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution.
Attacker Value
Unknown

CVE-2019-3975

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbitrary code via a crafted IOCTL 70603 RPC message.
Attacker Value
Unknown

CVE-2019-10961

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
Attacker Value
Unknown

CVE-2019-10991

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.