windriver records
48 published records for vendor windriver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.1%
- Pre-auth RCE
- 7
- With a fix record
- 6.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation7
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-190 Integer Overflow or Wraparound4
- CWE-787 Out-of-bounds Write3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-125 Out-of-bounds Read2
The weakness classes this vendor ships most often: where to look.
CWEAll records
48 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2019-12255Proof of concept | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).windriver · vxworks · CWE-120 | Critical9.8 | — | 75.3% | Aug 9, 2019 |
62This week | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Critical10.0 | — | 72.6% | Mar 7, 2003 |
60This week | CVE-2019-12257No exploit | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component.windriver · vxworks · CWE-120 | High8.8 | — | 84.2% | Aug 9, 2019 |
53Plan | CVE-2010-2965No exploit | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Critical9.8 | — | 47.4% | Aug 5, 2010 |
47Plan | CVE-2019-12256No exploit | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component.windriver · vxworks · CWE-120 | Critical9.8 | — | 26.6% | Aug 9, 2019 |
46Plan | CVE-2019-12260No exploit | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4).windriver · vxworks · CWE-120 | Critical9.8 | — | 22.8% | Aug 9, 2019 |
42Plan | CVE-2019-12261No exploit | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4).windriver · vxworks · CWE-120 | Critical9.8 | — | 9.0% | Aug 9, 2019 |
42Plan | CVE-2013-0714No exploit | IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of servwindriver · vxworks · CWE-20 | Critical10.0 | — | 6.4% | Mar 20, 2013 |
41Plan | CVE-2007-2736Proof of concept | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in thehp · hp-ux | Critical10.0 | — | 4.1% | May 17, 2007 |
40Plan | CVE-2019-12262No exploit | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component.windriver · vxworks | Critical9.8 | — | 4.1% | Aug 14, 2019 |
40Plan | CVE-2020-35198No exploit | An issue was discovered in Wind River VxWorks 7.windriver · vxworks · CWE-190 | Critical9.8 | — | 2.5% | May 12, 2021 |
40Plan | CVE-2021-29998No exploit | An issue was discovered in Wind River VxWorks before 6.5.windriver · vxworks · CWE-787 | Critical9.8 | — | 2.4% | Apr 13, 2021 |
40Plan | CVE-2016-20009No exploit | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7.windriver · vxworks · CWE-787 | Critical9.8 | — | 1.9% | Mar 11, 2021 |
40Plan | CVE-2021-29999No exploit | An issue was discovered in Wind River VxWorks through 6.8.windriver · vxworks · CWE-787 | Critical9.8 | — | 1.8% | Apr 13, 2021 |
39Monitor | CVE-2019-12265No exploit | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.windriver · vxworks · CWE-401 | Medium5.3 | — | 59.8% | Aug 9, 2019 |
39Monitor | CVE-2008-2476No exploit | The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 Fforce10 · ftos · CWE-20 | Critical9.3 | — | 7.4% | Oct 3, 2008 |
39Monitor | CVE-2020-10288No exploit | RVD#3327: No authentication required for accesing ABB IRC5 FTP serverabb · robotware · CWE-284 | Critical9.8 | — | 1.4% | Jul 15, 2020 |
37Monitor | CVE-2019-12258Weaponized | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component.windriver · vxworks · CWE-384 | High7.5 | — | 22.8% | Aug 9, 2019 |
35Monitor | CVE-2021-3450Proof of concept | CA certificate check bypass with X509_V_FLAG_X509_STRICTopenssl · openssl · CWE-295 | High7.4 | — | 18.3% | Mar 25, 2021 |
35Monitor | CVE-2007-4938Proof of concept | Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (appibm · aix · CWE-119 | High7.6 | — | 16.0% | Sep 18, 2007 |
35Monitor | CVE-2019-12259No exploit | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component.windriver · vxworks · CWE-476 | High7.5 | — | 15.9% | Aug 9, 2019 |
35Monitor | CVE-2023-38346No exploit | An issue was discovered in Wind River VxWorks 6.9 and 7.windriver · vxworks · CWE-22 | High8.8 | — | 1.5% | Sep 22, 2023 |
34Monitor | CVE-2015-7599No exploit | Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC)windriver · vxworks · CWE-190 | High8.1 | — | 5.9% | Feb 7, 2017 |
33Monitor | CVE-2007-1043Proof of concept | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and hp · hp-ux | High7.5 | — | 8.3% | Feb 21, 2007 |
33Monitor | CVE-2019-12263No exploit | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4).windriver · vxworks · CWE-362 | High8.1 | — | 3.2% | Aug 9, 2019 |
- CVE-2019-1225562This week
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).
CriticalCVSS 9.8Proof of conceptEPSS 75%windriver · vxworksAug 9, 2019
- CVE-2002-133762This week
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
CriticalCVSS 10.0Proof of conceptEPSS 73%sendmail · sendmailMar 7, 2003
- CVE-2019-1225760This week
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component.
HighCVSS 8.8No exploitEPSS 84%windriver · vxworksAug 9, 2019
- CVE-2010-296553Plan
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
CriticalCVSS 9.8No exploitEPSS 47%rockwellautomation · 1756-enbt\/a firmwareAug 5, 2010
- CVE-2019-1225647Plan
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component.
CriticalCVSS 9.8No exploitEPSS 27%windriver · vxworksAug 9, 2019
- CVE-2019-1226046Plan
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4).
CriticalCVSS 9.8No exploitEPSS 23%windriver · vxworksAug 9, 2019
- CVE-2019-1226142Plan
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4).
CriticalCVSS 9.8No exploitEPSS 9%windriver · vxworksAug 9, 2019
- CVE-2013-071442Plan
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of serv
CriticalCVSS 10.0No exploitEPSS 6%windriver · vxworksMar 20, 2013
- CVE-2007-273641Plan
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the
CriticalCVSS 10.0Proof of conceptEPSS 4%hp · hp-uxMay 17, 2007
- CVE-2019-1226240Plan
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component.
CriticalCVSS 9.8No exploitEPSS 4%windriver · vxworksAug 14, 2019
- CVE-2020-3519840Plan
An issue was discovered in Wind River VxWorks 7.
CriticalCVSS 9.8No exploitEPSS 2%windriver · vxworksMay 12, 2021
- CVE-2021-2999840Plan
An issue was discovered in Wind River VxWorks before 6.5.
CriticalCVSS 9.8No exploitEPSS 2%windriver · vxworksApr 13, 2021
- CVE-2016-2000940Plan
A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7.
CriticalCVSS 9.8No exploitEPSS 2%windriver · vxworksMar 11, 2021
- CVE-2021-2999940Plan
An issue was discovered in Wind River VxWorks through 6.8.
CriticalCVSS 9.8No exploitEPSS 2%windriver · vxworksApr 13, 2021
- CVE-2019-1226539Monitor
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.
MediumCVSS 5.3No exploitEPSS 60%windriver · vxworksAug 9, 2019
- CVE-2008-247639Monitor
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 F
CriticalCVSS 9.3No exploitEPSS 7%force10 · ftosOct 3, 2008
- CVE-2020-1028839Monitor
RVD#3327: No authentication required for accesing ABB IRC5 FTP server
CriticalCVSS 9.8No exploitEPSS 1%abb · robotwareJul 15, 2020
- CVE-2019-1225837Monitor
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component.
HighCVSS 7.5WeaponizedEPSS 23%windriver · vxworksAug 9, 2019
- CVE-2021-345035Monitor
CA certificate check bypass with X509_V_FLAG_X509_STRICT
HighCVSS 7.4Proof of conceptEPSS 18%openssl · opensslMar 25, 2021
- CVE-2007-493835Monitor
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (app
HighCVSS 7.6Proof of conceptEPSS 16%ibm · aixSep 18, 2007
- CVE-2019-1225935Monitor
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component.
HighCVSS 7.5No exploitEPSS 16%windriver · vxworksAug 9, 2019
- CVE-2023-3834635Monitor
An issue was discovered in Wind River VxWorks 6.9 and 7.
HighCVSS 8.8No exploitEPSS 2%windriver · vxworksSep 22, 2023
- CVE-2015-759934Monitor
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC)
HighCVSS 8.1No exploitEPSS 6%windriver · vxworksFeb 7, 2017
- CVE-2007-104333Monitor
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and
HighCVSS 7.5Proof of conceptEPSS 8%hp · hp-uxFeb 21, 2007
- CVE-2019-1226333Monitor
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4).
HighCVSS 8.1No exploitEPSS 3%windriver · vxworksAug 9, 2019