xArrow records
7 published records for vendor xarrow.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2012-2428No exploit | Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers axarrow · xarrow · CWE-189 | Critical10.0 | — | 4.5% | May 25, 2012 |
41Plan | CVE-2012-2427No exploit | Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger axarrow · xarrow · CWE-119 | Critical10.0 | — | 3.9% | May 25, 2012 |
41Plan | CVE-2012-2429No exploit | The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecifiexarrow · xarrow · CWE-189 | Critical10.0 | — | 3.8% | May 25, 2012 |
32Monitor | CVE-2012-2426No exploit | The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointexarrow · xarrow · CWE-399 | High7.8 | — | 2.2% | May 25, 2012 |
31Monitor | CVE-2021-33025No exploit | xArrow SCADA Path Traversalxarrow · xarrow · CWE-79 | High7.8 | — | 0.3% | May 16, 2022 |
24Monitor | CVE-2021-33001No exploit | xArrow SCADA Cross-site Scriptingxarrow · xarrow · CWE-79 | Medium6.1 | — | 0.8% | May 16, 2022 |
24Monitor | CVE-2021-33021No exploit | xArrow SCADA Cross-site Scriptingxarrow · xarrow · CWE-79 | Medium6.1 | — | 0.8% | May 16, 2022 |
- CVE-2012-242841Plan
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers a
CriticalCVSS 10.0No exploitEPSS 5%xarrow · xarrowMay 25, 2012
- CVE-2012-242741Plan
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger a
CriticalCVSS 10.0No exploitEPSS 4%xarrow · xarrowMay 25, 2012
- CVE-2012-242941Plan
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecifie
CriticalCVSS 10.0No exploitEPSS 4%xarrow · xarrowMay 25, 2012
- CVE-2012-242632Monitor
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointe
HighCVSS 7.8No exploitEPSS 2%xarrow · xarrowMay 25, 2012
- CVE-2021-3302531Monitor
xArrow SCADA Path Traversal
HighCVSS 7.8No exploitEPSS 0%xarrow · xarrowMay 16, 2022
- CVE-2021-3300124Monitor
xArrow SCADA Cross-site Scripting
MediumCVSS 6.1No exploitEPSS 1%xarrow · xarrowMay 16, 2022
- CVE-2021-3302124Monitor
xArrow SCADA Cross-site Scripting
MediumCVSS 6.1No exploitEPSS 1%xarrow · xarrowMay 16, 2022