CVE Vulnerability Database

Search and browse 124 known security vulnerabilities. Filter by severity, vendor, product, and year.

124 vulnerabilities found
CVE-2019-13533
8.1 high

In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

Omron Plc Cj Firmware Dec 16, 2019
CVE-2019-19378
7.8 high

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.

Linux Linux Kernel Nov 29, 2019
CVE-2019-13721
8.8 high

Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Google Chrome Nov 25, 2019
CVE-2019-6852
7.5 high

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP har

Schneider-Electric Bmx P34X Firmware Nov 20, 2019
CVE-2019-18197
7.5 high

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo

Xmlsoft Libxslt Oct 18, 2019
CVE-2019-10996
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that can reference memory after it has been freed.

Redlion Crimson Sep 23, 2019
CVE-2019-10984
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that causes the program to mishandle pointers.

Redlion Crimson Sep 23, 2019
CVE-2019-10978
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that operates outside of the designated memory area.

Redlion Crimson Sep 23, 2019
CVE-2019-6829
7.5 high

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

Schneider-Electric Modicon M580 Firmware Sep 17, 2019
CVE-2019-1010294
7.5 high

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2017-14853
8.6 high

The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and receive valid output from the device.

Orpak Siteomat Jun 3, 2019
CVE-2017-14852
8.6 high

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.

Orpak Siteomat Jun 3, 2019
CVE-2019-6819
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80

Schneider-Electric Modicon M340 Firmware May 22, 2019
CVE-2019-6820
8.2 high

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC

Schneider-Electric Modicon M100 Firmware May 22, 2019
CVE-2018-7852
7.5 high

A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.

Schneider-Electric Modicon M580 Firmware May 22, 2019
CVE-2018-7821
7.5 high

An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated.

Schneider-Electric Somachine Basic May 22, 2019
CVE-2019-11687
7.8 high

An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable headers for multiple operating systems, inclu

Nema Dicom Standard May 2, 2019
CVE-2019-10953
7.5 high

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Abb Pm554-Tp-Eth Firmware Apr 17, 2019
CVE-2019-6575
7.5 high

A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4

Siemens Simatic Cp443-1 Opc Ua Firmware Apr 17, 2019
CVE-2018-16561
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart. Successful exploitation requires an

Siemens Simatic S7-300 Firmware Apr 17, 2019
CVE-2017-15031
7.5 high

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.

Trustedfirmware Trusted Firmware-A Dec 18, 2018
CVE-2018-17924
8.6 high

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in

Rockwellautomation Micrologix 1400 Firmware Dec 7, 2018
CVE-2018-6439
7.8 high

A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.

Broadcom Fabric Operating System Dec 3, 2018
CVE-2018-7798
8.2 high

A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.

Schneider-Electric Somachine Basic Nov 2, 2018