Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2014-0765
To exploit this vulnerability, the attacker sends data from the GotoCmd
argument to control. If the value of the argument is overly long, the
stati…
Advantech Webaccess
after 7.1
HIGH 7.5
CVE-2014-0766
An attacker can exploit this vulnerability by copying an overly long
NodeName2 argument into a statically sized buffer on the stack to
overflow the…
Advantech Webaccess
after 7.1
HIGH 7.5
CVE-2014-0767
An attacker may exploit this vulnerability by passing an overly long
value from the AccessCode argument to the control. This will overflow
the stat…
Advantech Webaccess
after 7.1
HIGH 7.5
CVE-2014-0768
An attacker may pass an overly long value from the AccessCode2 argument
to the control to overflow the static stack buffer. The attacker may
then r…
Advantech Webaccess
after 7.1
HIGH 7.5
CVE-2014-0770
By providing an overly long string to the UserName parameter, an
attacker may be able to overflow the static stack buffer. The attacker
may then ex…
Advantech Webaccess
after 7.1
HIGH 7.5
CVE-2014-0773
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named
“CreateProcess.” This method contains validation to ensure an attacker
cannot run arbit…
Advantech Webaccess
after 7.1
MEDIUM 5.0
CVE-2014-0771
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named
“OpenUrlToBuffer.” This method takes a URL as a parameter and returns
its contents to t…
Advantech Webaccess
after 7.1
MEDIUM 5.0
CVE-2014-0772
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named
OpenUrlToBufferTimeout. This method takes a URL as a parameter and
returns its contents…
Advantech Webaccess
after 7.1
HIGH 7.8
CVE-2013-1627
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack…
Advantech Studio
Mitigation only
HIGH 10.0
CVE-2012-0238
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecifie…
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2012-0240
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbit…
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2012-0242EPSS 7%
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers…
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2012-0243
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by…
Advantech Webaccess
after 6.0
HIGH 7.5
CVE-2012-0244
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafte…
Advantech Webaccess
after 6.0
MEDIUM 6.5
CVE-2012-1234
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed U…
Advantech Webaccess
after 6.0
MEDIUM 6.4
CVE-2012-0237
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafte…
Advantech Webaccess
after 6.0
MEDIUM 6.0
CVE-2012-0235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of un…
Advantech Webaccess
after 6.0
MEDIUM 6.0
CVE-2012-1235
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to hijack the authentication of…
Advantech Webaccess
after 6.0
MEDIUM 5.0
CVE-2012-0236
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor…
Advantech Webaccess
after 6.0
MEDIUM 5.0
CVE-2012-0239
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an admin…
Advantech Webaccess
after 6.0
MEDIUM 5.0
CVE-2012-0241
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to …
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2011-4524
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified p…
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2011-4525
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client syst…
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2011-4526
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long st…
Advantech Webaccess
after 6.0
HIGH 7.5
CVE-2012-0234
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2011-1914
Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server …
Adam Opc Server
after 3.01.011
HIGH 7.5
CVE-2011-4521
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string i…
Advantech Webaccess
after 6.0
HIGH 9.3
CVE-2011-0340EPSS 32%
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distribute…
Advantech Studio
after 7.0
HIGH 10.0
CVE-2011-0488EPSS 9%
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft W…
Advantech Studio
Patch available
HIGH 10.0
CVE-2008-5848
The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP sess…
Adam 6015
Mitigation only