Ecava records
26 published records for vendor ecava.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-310 Cryptographic Issues1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2010-4597Proof of concept | Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Intecava · integraxor · CWE-119 | Critical10.0 | — | 18.8% | Dec 23, 2010 |
40Plan | CVE-2017-6050No exploit | A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.ecava · integraxor · CWE-89 | Critical9.8 | — | 3.5% | Jun 21, 2017 |
39Monitor | CVE-2012-0246No exploit | Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute ecava · integraxor · CWE-22 | Critical9.3 | — | 5.9% | Apr 2, 2012 |
39Monitor | CVE-2016-8341No exploit | An issue was discovered in Ecava IntegraXor Version 5.0.413.0.ecava · integraxor · CWE-89 | Critical9.8 | — | 1.7% | Feb 13, 2017 |
38Monitor | CVE-2012-4700No exploit | Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackecava · integraxor · CWE-119 | Critical9.3 | — | 3.8% | Feb 8, 2013 |
37Monitor | CVE-2014-2375No exploit | Ecava IntegraXor SCADA Server External Control of File Name or Pathecava · integraxor · CWE-73 | Critical9.0 | — | 2.3% | Sep 15, 2014 |
32Monitor | CVE-2014-0753No exploit | Ecava IntegraXor Stack-based Buffer Overflowecava · integraxor · CWE-121 | High7.8 | — | 2.5% | Jan 20, 2014 |
31Monitor | CVE-2014-2376No exploit | Ecava IntegraXor SCADA Server SQL Injectionecava · integraxor · CWE-89 | High7.5 | — | 2.0% | Sep 15, 2014 |
31Monitor | CVE-2016-2306No exploit | The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing tecava · integraxor · CWE-310 | High7.5 | — | 1.9% | Apr 21, 2016 |
31Monitor | CVE-2011-1562No exploit | Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unecava · integraxor · CWE-89 | High7.5 | — | 1.7% | Apr 5, 2011 |
29Monitor | CVE-2016-2299No exploit | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecifecava · integraxor · CWE-89 | High7.3 | — | 1.4% | Apr 21, 2016 |
28Monitor | CVE-2010-4598Proof of concept | Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..ecava · integraxor · CWE-22 | Medium5.0 | — | 26.5% | Dec 23, 2010 |
27Monitor | CVE-2010-4599No exploit | Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file ecava · integraxor | Medium6.9 | — | 0.3% | Dec 23, 2010 |
26Monitor | CVE-2016-2300No exploit | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectorsecava · integraxor · CWE-287 | Medium6.5 | — | 1.2% | Apr 21, 2016 |
25Monitor | CVE-2016-2301No exploit | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands viecava · integraxor · CWE-89 | Medium6.3 | — | 0.8% | Apr 21, 2016 |
24Monitor | CVE-2016-2305No exploit | Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script orecava · integraxor · CWE-79 | Medium6.1 | — | 0.9% | Apr 21, 2016 |
21Monitor | CVE-2014-0786No exploit | Ecava IntegraXor Information Exposureecava · integraxor · CWE-200 | Medium5.0 | — | 2.7% | Apr 30, 2014 |
21Monitor | CVE-2014-2377No exploit | Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variablesecava · integraxor · CWE-526 | Medium5.0 | — | 1.8% | Sep 15, 2014 |
21Monitor | CVE-2016-2302No exploit | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.ecava · integraxor · CWE-200 | Medium5.3 | — | 1.2% | Apr 21, 2016 |
21Monitor | CVE-2016-2303No exploit | CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct ecava · integraxor | Medium5.3 | — | 1.1% | Apr 21, 2016 |
21Monitor | CVE-2017-16735No exploit | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.ecava · integraxor · CWE-89 | Medium5.3 | — | 1.0% | Dec 20, 2017 |
21Monitor | CVE-2017-16733No exploit | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.ecava · integraxor · CWE-89 | Medium5.3 | — | 0.9% | Dec 20, 2017 |
20Monitor | CVE-2014-0752No exploit | Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphereecava · integraxor · CWE-529 | Medium5.0 | — | 1.6% | Jan 9, 2014 |
17Monitor | CVE-2011-2958No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary ecava · integraxor · CWE-79 | Medium4.3 | — | 1.2% | Jul 28, 2011 |
17Monitor | CVE-2016-2304No exploit | Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easiecava · integraxor · CWE-200 | Medium4.3 | — | 1.1% | Apr 21, 2016 |
- CVE-2010-459746Plan
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Int
CriticalCVSS 10.0Proof of conceptEPSS 19%ecava · integraxorDec 23, 2010
- CVE-2017-605040Plan
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.
CriticalCVSS 9.8No exploitEPSS 4%ecava · integraxorJun 21, 2017
- CVE-2012-024639Monitor
Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute
CriticalCVSS 9.3No exploitEPSS 6%ecava · integraxorApr 2, 2012
- CVE-2016-834139Monitor
An issue was discovered in Ecava IntegraXor Version 5.0.413.0.
CriticalCVSS 9.8No exploitEPSS 2%ecava · integraxorFeb 13, 2017
- CVE-2012-470038Monitor
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attack
CriticalCVSS 9.3No exploitEPSS 4%ecava · integraxorFeb 8, 2013
- CVE-2014-237537Monitor
Ecava IntegraXor SCADA Server External Control of File Name or Path
CriticalCVSS 9.0No exploitEPSS 2%ecava · integraxorSep 15, 2014
- CVE-2014-075332Monitor
Ecava IntegraXor Stack-based Buffer Overflow
HighCVSS 7.8No exploitEPSS 3%ecava · integraxorJan 20, 2014
- CVE-2014-237631Monitor
Ecava IntegraXor SCADA Server SQL Injection
HighCVSS 7.5No exploitEPSS 2%ecava · integraxorSep 15, 2014
- CVE-2016-230631Monitor
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing t
HighCVSS 7.5No exploitEPSS 2%ecava · integraxorApr 21, 2016
- CVE-2011-156231Monitor
Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via un
HighCVSS 7.5No exploitEPSS 2%ecava · integraxorApr 5, 2011
- CVE-2016-229929Monitor
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecif
HighCVSS 7.3No exploitEPSS 1%ecava · integraxorApr 21, 2016
- CVE-2010-459828Monitor
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 26%ecava · integraxorDec 23, 2010
- CVE-2010-459927Monitor
Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file
MediumCVSS 6.9No exploitEPSS 0%ecava · integraxorDec 23, 2010
- CVE-2016-230026Monitor
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors
MediumCVSS 6.5No exploitEPSS 1%ecava · integraxorApr 21, 2016
- CVE-2016-230125Monitor
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands vi
MediumCVSS 6.3No exploitEPSS 1%ecava · integraxorApr 21, 2016
- CVE-2016-230524Monitor
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or
MediumCVSS 6.1No exploitEPSS 1%ecava · integraxorApr 21, 2016
- CVE-2014-078621Monitor
Ecava IntegraXor Information Exposure
MediumCVSS 5.0No exploitEPSS 3%ecava · integraxorApr 30, 2014
- CVE-2014-237721Monitor
Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables
MediumCVSS 5.0No exploitEPSS 2%ecava · integraxorSep 15, 2014
- CVE-2016-230221Monitor
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
MediumCVSS 5.3No exploitEPSS 1%ecava · integraxorApr 21, 2016
- CVE-2016-230321Monitor
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct
MediumCVSS 5.3No exploitEPSS 1%ecava · integraxorApr 21, 2016
- CVE-2017-1673521Monitor
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.
MediumCVSS 5.3No exploitEPSS 1%ecava · integraxorDec 20, 2017
- CVE-2017-1673321Monitor
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.
MediumCVSS 5.3No exploitEPSS 1%ecava · integraxorDec 20, 2017
- CVE-2014-075220Monitor
Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere
MediumCVSS 5.0No exploitEPSS 2%ecava · integraxorJan 9, 2014
- CVE-2011-295817Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 1%ecava · integraxorJul 28, 2011
- CVE-2016-230417Monitor
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi
MediumCVSS 4.3No exploitEPSS 1%ecava · integraxorApr 21, 2016