Show filters
132 Total Results
Displaying 81-90 of 132
Sort by:
Attacker Value
Unknown
CVE-2021-34584
Disclosure Date: October 25, 2021 (last updated February 23, 2025)
Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
0
Attacker Value
Unknown
CVE-2021-34585
Disclosure Date: October 25, 2021 (last updated February 23, 2025)
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.
0
Attacker Value
Unknown
CVE-2021-34586
Disclosure Date: October 25, 2021 (last updated February 23, 2025)
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2021-21869
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21867
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21868
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21863
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-36764
Disclosure Date: August 04, 2021 (last updated February 23, 2025)
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2021-36765
Disclosure Date: August 04, 2021 (last updated February 23, 2025)
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.
0
Attacker Value
Unknown
CVE-2021-33486
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
0