Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libiec61850 CRITICAL 9.8
CVE-2024-45970

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious ser…

Fix: 1.6.0+
Fix from $2,300 2024-11-15
Libiec61850 CRITICAL 9.8
CVE-2024-45971

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious ser…

Fix: 1.6.0+
Fix from $2,300 2024-11-15
Libiec61850 HIGH 7.4
CVE-2024-36702

libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.

No fix yet
Fix from $1,950 2024-06-11
Libiec61850 HIGH 7.5
CVE-2024-28286

In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/se…

No fix yet
Fix from $1,950 2024-03-21
Libiec61850 HIGH 7.5
CVE-2024-26529

An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteN…

Fix: after 1.5.3
Fix from $1,950 2024-03-13
Libiec61850 MEDIUM 6.2
CVE-2024-25366

Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleG…

No fix yet
Fix from $1,600 2024-02-20
Libiec61850 HIGH 7.5
CVE-2023-27772

libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c.

Patch available
Fix from $1,950 2023-04-13
Lib60870 MEDIUM 5.5
CVE-2023-23205

An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.

No fix yet
Fix from $1,600 2023-02-24
Libiec61850 HIGH 8.8
CVE-2022-3976

A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability affects unknown code of the file…

Fix: 1.5+
Fix from $1,950 2022-11-13
Libiec61850 HIGH 7.5
CVE-2022-2973

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) uses a NULL pointer in cer…

Fix: 1.5.0+
Fix from $1,950 2022-09-23
Libiec61850 CRITICAL 9.8
CVE-2022-2970

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input be…

Fix: 1.5.0+
Fix from $2,300 2022-09-23
Libiec61850 CRITICAL 9.8
CVE-2022-2972

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-b…

Fix: 1.5.0+
Fix from $2,300 2022-09-23
Libiec61850 HIGH 7.5
CVE-2022-2971

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) accesses a resource using …

Fix: 1.5.0+
Fix from $1,950 2022-09-23
Libiec61850 HIGH 7.5
CVE-2022-21159

A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec61850 1.5.0. A specially-crafted …

Patch available
Fix from $1,950 2022-04-15
Libiec61850 HIGH 7.5
CVE-2022-1302

In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which may result in a denial of se…

Fix: 1.5.1+
Fix from $1,950 2022-04-12
Libiec61850 HIGH 7.5
CVE-2021-45769

A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or applic…

Patch available
Fix from $1,950 2022-01-14
Lib60870 HIGH 7.5
CVE-2021-45773

A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation…

Fix: 2.3.1+
Fix from $1,950 2022-01-14
Lib60870 HIGH 7.5
CVE-2021-21778

A denial of service vulnerability exists in the ASDU message processing functionality of MZ Automation GmbH lib60870.NET 2.2.0. A specially crafted n…

No fix yet
Fix from $1,950 2021-08-25
Libiec61850 CRITICAL 9.8
CVE-2020-15158

In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leadin…

Fix: 1.4.3+
Fix from $2,300 2020-08-26
Libiec61850 HIGH 8.8
CVE-2020-7054

MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_B…

Fix: after 1.4.0
Fix from $1,950 2020-01-14
Libiec61850 MEDIUM 6.5
CVE-2019-19957

In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and el…

No fix yet
Fix from $1,600 2019-12-24
Libiec61850 MEDIUM 6.5
CVE-2019-19958

In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted…

No fix yet
Fix from $1,600 2019-12-24
Libiec61850 MEDIUM 6.5
CVE-2019-19944

In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.

No fix yet
Fix from $1,600 2019-12-23
Libiec61850 HIGH 8.8
CVE-2019-19931

In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.

No fix yet
Fix from $1,950 2019-12-23
Libiec61850 MEDIUM 6.5
CVE-2019-19930

In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessi…

No fix yet
Fix from $1,600 2019-12-23
Libiec61850 HIGH 7.5
CVE-2019-16510

libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.

Fix: after 1.3.3
Fix from $1,950 2019-09-19
Libiec61850 HIGH 7.5
CVE-2019-1010300

mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_…

No fix yet
Fix from $1,950 2019-07-15
Libiec61850 HIGH 7.5
CVE-2019-6719

An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_server.c, as demonstrated by …

No fix yet
Fix from $1,950 2019-01-23
Libiec61850 HIGH 7.5
CVE-2019-6135

An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called from Asn1PrimitiveValue_create …

No fix yet
Fix from $1,950 2019-01-11
Libiec61850 HIGH 7.5
CVE-2019-6136

An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a SEGV, as demonstrated by sv_su…

No fix yet
Fix from $1,950 2019-01-11