Threat Encyclopedia

    ICS Tri PLC Nano 10 PLC Denial of Service (CVE-2013-2784)

    Triangle Research International Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbus/TCP packets, which allows remote attackers to cause a denial of service .

    Updated At: 2025/05/07


    ICS RIO 47100 PLC Denial of Service (CVE-2013-0699)

    The vulnerability is due to insufficient boundary checking of coil number in Modbus packets. A remote attacker can take advantage of this vulnerability to crash the PLC.

    Updated At: 2025/05/07


    ICS Advantech WebAccess SCADA webvact.ocx AccessCode/AccessCode2 Buffer Overflow -1 (CVE-2014-0767)

    A stack buffer overflow exists in Advantech's WebAccess SCADA software. This is due to insufficient input validation on the AccessCode2 parameter of the webvact.ocx ActiveX control, a part of the WebAccess Client.

    Updated At: 2025/05/07


    ICS KingView ActiveX Control File Execution -2 (CVE-2013-6128)

    WellinTech KingView is prone to multiple insecure-method vulnerabilities because it fails to properly sanitize user-supplied input.

    Updated At: 2025/05/07


    ICS Advantech WebAccess SCADA webvact.ocx AccessCode/AccessCode2 Buffer Overflow -2 (CVE-2014-0767)

    A stack buffer overflow exists in Advantech's WebAccess SCADA software. This is due to insufficient input validation on the AccessCode2 parameter of the webvact.ocx ActiveX control, a part of the WebAccess Client.

    Updated At: 2025/05/07


    ICS Advantech WebAccess SCADA webvact.ocx AccessCode/AccessCode2 Buffer Overflow -3 (CVE-2014-0767)

    A stack buffer overflow exists in Advantech's WebAccess SCADA software. This is due to insufficient input validation on the AccessCode2 parameter of the webvact.ocx ActiveX control, a part of the WebAccess Client.

    Updated At: 2025/05/07


    ICS KingView ActiveX Control File Execution -1 (CVE-2013-6128)

    WellinTech KingView is prone to multiple insecure-method vulnerabilities because it fails to properly sanitize user-supplied input.

    Updated At: 2025/05/07


    ICS Advantech/BroadWin WebAccess ActiveX Clsid Access (CVE-2012-0242)

    Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.

    Updated At: 2025/05/07


    WEB CyberPanel Multi CVE Pre-auth RCE (CVE-2024-51568)

    CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

    Updated At: 2025/05/07


    ICS Advantech/BroadWin WebAccess Function Call Access (CVE-2012-0242)

    Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.

    Updated At: 2025/05/07


    ICS Schneider Electric Vijeo Historian Web Server Multiple Vulnerabilities (CVE-2011-4034)

    The flaw is due to insufficient validation of input to the AddSeries property in the TeeChart ActiveX control. By enticing a user to visit a malicious web page, arbitrary code can be executed on the client system.

    Updated At: 2025/05/07


    WEB Langflow AI unauthenticated code injection RCE (CVE-2025-3248)

    Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

    Updated At: 2025/05/07


    ICS Sante PACS Server URL path Denial-of-Service Vulnerability (CVE-2025-0574)

    The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted URL path.

    Updated At: 2025/05/06


    FILE Ghostscript pipe devices OS Command Injection (CVE-2023-36664)

    Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

    Updated At: 2025/04/30


    ICS Advantech WebAccess DCE/RPC webvrpcs Service Stack Buffer Overflow 2006 (CVE-2017-14016)

    The vulnerability is due to lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. A specially crafted DCE/RPC request can overflow a buffer, which could lead to arbitrary code execution or abnormal termination within the context of the WebAccess process.

    Updated At: 2025/04/30


    ICS Mitsubishi MCWorkX ActiveX Control File Execution -2 (CVE-2013-2817)

    Mitsubishi MC-WorX is prone to a remote code-execution vulnerability.

    Updated At: 2025/04/30


    ICS Mitsubishi MCWorkX ActiveX Control File Execution -1 (CVE-2013-2817)

    Mitsubishi MC-WorX is prone to a remote code-execution vulnerability.

    Updated At: 2025/04/30


    ICS ScadaTEC ScadaPhone Stack Buffer Overflow -2 (CVE-2011-4535)

    A stack-based buffer overflow vulnerability was found in version 5.3.11.1230 of scadaTEC's ScadaPhone. In order for the command to be executed, an attacker must convince someone to load a specially crafted project zip file with ScadaPhone.

    Updated At: 2025/04/30


    ICS InduSoft Web Studio Remote Agent Buffer Overflow (CVE-2011-4052)

    A stack-based buffer overflow vulnerability has been identified in the Remote Agent component of InduSoft Web Studio. The vulnerability is due to an insufficient boundary check when copying user supplied data with the "Remove File" (0x15) operation.

    Updated At: 2025/04/30


    ICS Sielco Sistemi Winlog Buffer Overflow (CVE-2011-0517)

    A buffer overflow vulnerability was found in Sielco Sistem Winlog <= 2.07.00. When sending a specially formatted packet to the Runtime.exe service, an attacker may be able to execute arbitrary code.

    Updated At: 2025/04/30


This website uses cookies to ensure you get the best experience on our website.

Learn more