Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advantech Webaccess HIGH 7.5
CVE-2014-0765

To exploit this vulnerability, the attacker sends data from the GotoCmd argument to control. If the value of the argument is overly long, the stati…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess HIGH 7.5
CVE-2014-0766

An attacker can exploit this vulnerability by copying an overly long NodeName2 argument into a statically sized buffer on the stack to overflow the…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess HIGH 7.5
CVE-2014-0767

An attacker may exploit this vulnerability by passing an overly long value from the AccessCode argument to the control. This will overflow the stat…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess HIGH 7.5
CVE-2014-0768

An attacker may pass an overly long value from the AccessCode2 argument to the control to overflow the static stack buffer. The attacker may then r…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess HIGH 7.5
CVE-2014-0770

By providing an overly long string to the UserName parameter, an attacker may be able to overflow the static stack buffer. The attacker may then ex…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess HIGH 7.5
CVE-2014-0773

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbit…

Fix: after 7.1
Fix from $1,950 2014-04-12
Advantech Webaccess MEDIUM 5.0
CVE-2014-0771

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to t…

Fix: after 7.1
Fix from $1,600 2014-04-12
Advantech Webaccess MEDIUM 5.0
CVE-2014-0772

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents…

Fix: after 7.1
Fix from $1,600 2014-04-12
Advantech Studio HIGH 7.8
CVE-2013-1627

Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack…

Mitigation only
Fix from $1,950 2013-03-11
Advantech Webaccess HIGH 10.0
CVE-2012-0238

Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecifie…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2012-0240

GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbit…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2012-0242EPSS 7%

Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2012-0243

Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 7.5
CVE-2012-0244

Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafte…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess MEDIUM 6.5
CVE-2012-1234

SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed U…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 6.4
CVE-2012-0237

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafte…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 6.0
CVE-2012-0235

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of un…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 6.0
CVE-2012-1235

Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 5.0
CVE-2012-0236

Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 5.0
CVE-2012-0239

uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an admin…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess MEDIUM 5.0
CVE-2012-0241

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to …

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2011-4524

Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified p…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2011-4525

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client syst…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2011-4526

Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long st…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 7.5
CVE-2012-0234

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.

Fix: after 6.0
Fix from $1,950 2012-02-21
Adam Opc Server HIGH 10.0
CVE-2011-1914

Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server …

Fix: after 3.01.011
Fix from $1,950 2012-02-21
Advantech Webaccess HIGH 7.5
CVE-2011-4521

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string i…

Fix: after 6.0
Fix from $1,950 2012-02-21
Advantech Studio HIGH 9.3
CVE-2011-0340EPSS 32%

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distribute…

Fix: after 7.0
Fix from $1,950 2011-05-04
Advantech Studio HIGH 10.0
CVE-2011-0488EPSS 9%

Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft W…

Patch available
Fix from $1,950 2011-01-18
Adam 6015 HIGH 10.0
CVE-2008-5848

The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP sess…

Mitigation only
Fix from $1,950 2009-01-06