WellinTech records
20 published records for vendor wellintech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 10%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-121 Stack-based Buffer Overflow1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2012-4711Weaponized | Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.ewellintech · kingview · CWE-119 | Critical10.0 | — | 61.5% | Feb 15, 2013 |
52Plan | CVE-2011-3142Proof of concept | Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arwellintech · kingview · CWE-119 | Critical10.0 | — | 38.4% | Aug 16, 2011 |
46Plan | CVE-2011-0406Proof of concept | Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long requeswellintech · kingview · CWE-119 | Critical10.0 | — | 21.3% | Jan 10, 2011 |
45Plan | CVE-2012-1831Proof of concept | Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 55wellintech · kingview · CWE-119 | Critical10.0 | — | 15.9% | Jul 4, 2012 |
44Plan | CVE-2013-2827Weaponized | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote wellintech · kingalarm\&event · CWE-94 | High7.5 | — | 48.3% | Jan 15, 2014 |
44Plan | CVE-2014-0787Proof of concept | WellinTech KingSCADA Stack-based Buffer Overflowwellintech · kingscada · CWE-121 | Critical10.0 | — | 14.1% | Apr 12, 2014 |
43Plan | CVE-2022-43663No exploit | An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05.wellintech · kinghistorian · CWE-195 | Critical9.8 | — | 14.0% | Mar 20, 2023 |
43Plan | CVE-2011-4536No exploit | Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 allwellintech · kingview · CWE-119 | Critical10.0 | — | 8.5% | Dec 27, 2011 |
42Plan | CVE-2012-1830Proof of concept | Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5wellintech · kingview · CWE-119 | Critical10.0 | — | 7.7% | Jul 4, 2012 |
42Plan | CVE-2012-1832No exploit | WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted pwellintech · kingview · CWE-119 | Critical10.0 | — | 5.9% | Jul 4, 2012 |
41Plan | CVE-2012-2559No exploit | WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crwellintech · kinghistorian · CWE-399 | Critical10.0 | — | 4.6% | Jul 4, 2012 |
38Monitor | CVE-2012-1819No exploit | Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current wellintech · kingview | Critical9.3 | — | 1.7% | May 2, 2012 |
34Monitor | CVE-2022-45124No exploit | An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05.wellintech · kinghistorian · CWE-200 | High7.5 | — | 13.4% | Mar 20, 2023 |
30Monitor | CVE-2018-20410No exploit | WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow.wellintech · kingscada · CWE-787 | High7.5 | — | 1.6% | Dec 23, 2018 |
28Monitor | CVE-2012-1977No exploit | WellinTech KingSCADA Missing Encryption of Sensitive Datawellintech · kingview · CWE-311 | High7.1 | — | 0.8% | May 9, 2012 |
27Monitor | CVE-2013-6127Proof of concept | The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly rewellintech · kingview · CWE-22 | Medium5.8 | — | 13.9% | Oct 25, 2013 |
26Monitor | CVE-2013-2826No exploit | WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager cwellintech · kingalarm\&event · CWE-264 | Medium6.4 | — | 1.8% | Jan 15, 2014 |
24Monitor | CVE-2013-6128Proof of concept | The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrwellintech · kingview · CWE-264 | Medium5.8 | — | 2.6% | Oct 25, 2013 |
21Monitor | CVE-2012-2560No exploit | Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to wellintech · kingview · CWE-22 | Medium5.0 | — | 2.6% | Jul 4, 2012 |
8Monitor | CVE-2012-4899No exploit | WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials wellintech · kingview · CWE-310 | Low2.1 | — | 0.3% | Oct 10, 2012 |
- CVE-2012-471158Plan
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.e
CriticalCVSS 10.0WeaponizedEPSS 61%wellintech · kingviewFeb 15, 2013
- CVE-2011-314252Plan
Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute ar
CriticalCVSS 10.0Proof of conceptEPSS 38%wellintech · kingviewAug 16, 2011
- CVE-2011-040646Plan
Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long reques
CriticalCVSS 10.0Proof of conceptEPSS 21%wellintech · kingviewJan 10, 2011
- CVE-2012-183145Plan
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 55
CriticalCVSS 10.0Proof of conceptEPSS 16%wellintech · kingviewJul 4, 2012
- CVE-2013-282744Plan
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote
HighCVSS 7.5WeaponizedEPSS 48%wellintech · kingalarm\&eventJan 15, 2014
- CVE-2014-078744Plan
WellinTech KingSCADA Stack-based Buffer Overflow
CriticalCVSS 10.0Proof of conceptEPSS 14%wellintech · kingscadaApr 12, 2014
- CVE-2022-4366343Plan
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05.
CriticalCVSS 9.8No exploitEPSS 14%wellintech · kinghistorianMar 20, 2023
- CVE-2011-453643Plan
Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 all
CriticalCVSS 10.0No exploitEPSS 9%wellintech · kingviewDec 27, 2011
- CVE-2012-183042Plan
Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5
CriticalCVSS 10.0Proof of conceptEPSS 8%wellintech · kingviewJul 4, 2012
- CVE-2012-183242Plan
WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted p
CriticalCVSS 10.0No exploitEPSS 6%wellintech · kingviewJul 4, 2012
- CVE-2012-255941Plan
WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a cr
CriticalCVSS 10.0No exploitEPSS 5%wellintech · kinghistorianJul 4, 2012
- CVE-2012-181938Monitor
Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current
CriticalCVSS 9.3No exploitEPSS 2%wellintech · kingviewMay 2, 2012
- CVE-2022-4512434Monitor
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05.
HighCVSS 7.5No exploitEPSS 13%wellintech · kinghistorianMar 20, 2023
- CVE-2018-2041030Monitor
WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow.
HighCVSS 7.5No exploitEPSS 2%wellintech · kingscadaDec 23, 2018
- CVE-2012-197728Monitor
WellinTech KingSCADA Missing Encryption of Sensitive Data
HighCVSS 7.1No exploitEPSS 1%wellintech · kingviewMay 9, 2012
- CVE-2013-612727Monitor
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly re
MediumCVSS 5.8Proof of conceptEPSS 14%wellintech · kingviewOct 25, 2013
- CVE-2013-282626Monitor
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager c
MediumCVSS 6.4No exploitEPSS 2%wellintech · kingalarm\&eventJan 15, 2014
- CVE-2013-612824Monitor
The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restr
MediumCVSS 5.8Proof of conceptEPSS 3%wellintech · kingviewOct 25, 2013
- CVE-2012-256021Monitor
Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to
MediumCVSS 5.0No exploitEPSS 3%wellintech · kingviewJul 4, 2012
- CVE-2012-48998Monitor
WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials
LowCVSS 2.1No exploitEPSS 0%wellintech · kingviewOct 10, 2012