Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xarrow HIGH 7.8
CVE-2021-33025

xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

Fix: after 7.2
Fix from $1,950 2022-05-16
Xarrow MEDIUM 6.1
CVE-2021-33001

xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an …

Fix: after 7.2
Fix from $1,600 2022-05-16
Xarrow MEDIUM 6.1
CVE-2021-33021

xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an …

Fix: after 7.2
Fix from $1,600 2022-05-16
Xarrow HIGH 10.0
CVE-2012-2427

Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid…

Fix: after 3.4
Fix from $1,950 2012-05-25
Xarrow HIGH 10.0
CVE-2012-2428

Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-…

Fix: after 3.4
Fix from $1,950 2012-05-25
Xarrow HIGH 10.0
CVE-2012-2429

The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 3.4
Fix from $1,950 2012-05-25
Xarrow HIGH 7.8
CVE-2012-2426

The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer derefer…

Fix: after 3.4
Fix from $1,950 2012-05-25