Skip to content
Noroxi

Ecava records

26 published records for vendor ecava.

All records

26 records
  • Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Int

    CriticalCVSS 10.0Proof of conceptEPSS 19%

    ecava · integraxorDec 23, 2010

  • A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.

    CriticalCVSS 9.8No exploitEPSS 4%

    ecava · integraxorJun 21, 2017

  • CVE-2012-0246
    39Monitor

    Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute

    CriticalCVSS 9.3No exploitEPSS 6%

    ecava · integraxorApr 2, 2012

  • CVE-2016-8341
    39Monitor

    An issue was discovered in Ecava IntegraXor Version 5.0.413.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    ecava · integraxorFeb 13, 2017

  • CVE-2012-4700
    38Monitor

    Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attack

    CriticalCVSS 9.3No exploitEPSS 4%

    ecava · integraxorFeb 8, 2013

  • CVE-2014-2375
    37Monitor

    Ecava IntegraXor SCADA Server External Control of File Name or Path

    CriticalCVSS 9.0No exploitEPSS 2%

    ecava · integraxorSep 15, 2014

  • CVE-2014-0753
    32Monitor

    Ecava IntegraXor Stack-based Buffer Overflow

    HighCVSS 7.8No exploitEPSS 3%

    ecava · integraxorJan 20, 2014

  • CVE-2014-2376
    31Monitor

    Ecava IntegraXor SCADA Server SQL Injection

    HighCVSS 7.5No exploitEPSS 2%

    ecava · integraxorSep 15, 2014

  • CVE-2016-2306
    31Monitor

    The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing t

    HighCVSS 7.5No exploitEPSS 2%

    ecava · integraxorApr 21, 2016

  • CVE-2011-1562
    31Monitor

    Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via un

    HighCVSS 7.5No exploitEPSS 2%

    ecava · integraxorApr 5, 2011

  • CVE-2016-2299
    29Monitor

    SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecif

    HighCVSS 7.3No exploitEPSS 1%

    ecava · integraxorApr 21, 2016

  • CVE-2010-4598
    28Monitor

    Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0Proof of conceptEPSS 26%

    ecava · integraxorDec 23, 2010

  • CVE-2010-4599
    27Monitor

    Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file

    MediumCVSS 6.9No exploitEPSS 0%

    ecava · integraxorDec 23, 2010

  • CVE-2016-2300
    26Monitor

    Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors

    MediumCVSS 6.5No exploitEPSS 1%

    ecava · integraxorApr 21, 2016

  • CVE-2016-2301
    25Monitor

    SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands vi

    MediumCVSS 6.3No exploitEPSS 1%

    ecava · integraxorApr 21, 2016

  • CVE-2016-2305
    24Monitor

    Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or

    MediumCVSS 6.1No exploitEPSS 1%

    ecava · integraxorApr 21, 2016

  • CVE-2014-0786
    21Monitor

    Ecava IntegraXor Information Exposure

    MediumCVSS 5.0No exploitEPSS 3%

    ecava · integraxorApr 30, 2014

  • CVE-2014-2377
    21Monitor

    Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables

    MediumCVSS 5.0No exploitEPSS 2%

    ecava · integraxorSep 15, 2014

  • CVE-2016-2302
    21Monitor

    Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.

    MediumCVSS 5.3No exploitEPSS 1%

    ecava · integraxorApr 21, 2016

  • CVE-2016-2303
    21Monitor

    CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct

    MediumCVSS 5.3No exploitEPSS 1%

    ecava · integraxorApr 21, 2016

  • A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.

    MediumCVSS 5.3No exploitEPSS 1%

    ecava · integraxorDec 20, 2017

  • A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.

    MediumCVSS 5.3No exploitEPSS 1%

    ecava · integraxorDec 20, 2017

  • CVE-2014-0752
    20Monitor

    Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere

    MediumCVSS 5.0No exploitEPSS 2%

    ecava · integraxorJan 9, 2014

  • CVE-2011-2958
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary

    MediumCVSS 4.3No exploitEPSS 1%

    ecava · integraxorJul 28, 2011

  • CVE-2016-2304
    17Monitor

    Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi

    MediumCVSS 4.3No exploitEPSS 1%

    ecava · integraxorApr 21, 2016