Записи WellinTech
20 опубликованных записей вендора wellintech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 10 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-121 Stack-based Buffer Overflow1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2012-4711Готовый эксплойт | Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.ewellintech · kingview · CWE-119 | Критическая10,0 | — | 61,5 % | 15 февр. 2013 г. |
52В плане | CVE-2011-3142Proof of concept | Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arwellintech · kingview · CWE-119 | Критическая10,0 | — | 38,4 % | 16 авг. 2011 г. |
46В плане | CVE-2011-0406Proof of concept | Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long requeswellintech · kingview · CWE-119 | Критическая10,0 | — | 21,3 % | 10 янв. 2011 г. |
45В плане | CVE-2012-1831Proof of concept | Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 55wellintech · kingview · CWE-119 | Критическая10,0 | — | 15,9 % | 4 июл. 2012 г. |
44В плане | CVE-2013-2827Готовый эксплойт | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote wellintech · kingalarm\&event · CWE-94 | Высокая7,5 | — | 48,3 % | 15 янв. 2014 г. |
44В плане | CVE-2014-0787Proof of concept | WellinTech KingSCADA Stack-based Buffer Overflowwellintech · kingscada · CWE-121 | Критическая10,0 | — | 14,1 % | 12 апр. 2014 г. |
43В плане | CVE-2022-43663Эксплойта нет | An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05.wellintech · kinghistorian · CWE-195 | Критическая9,8 | — | 14,0 % | 20 мар. 2023 г. |
43В плане | CVE-2011-4536Эксплойта нет | Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 allwellintech · kingview · CWE-119 | Критическая10,0 | — | 8,5 % | 27 дек. 2011 г. |
42В плане | CVE-2012-1830Proof of concept | Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5wellintech · kingview · CWE-119 | Критическая10,0 | — | 7,7 % | 4 июл. 2012 г. |
42В плане | CVE-2012-1832Эксплойта нет | WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted pwellintech · kingview · CWE-119 | Критическая10,0 | — | 5,9 % | 4 июл. 2012 г. |
41В плане | CVE-2012-2559Эксплойта нет | WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crwellintech · kinghistorian · CWE-399 | Критическая10,0 | — | 4,6 % | 4 июл. 2012 г. |
38Наблюдать | CVE-2012-1819Эксплойта нет | Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current wellintech · kingview | Критическая9,3 | — | 1,7 % | 2 мая 2012 г. |
34Наблюдать | CVE-2022-45124Эксплойта нет | An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05.wellintech · kinghistorian · CWE-200 | Высокая7,5 | — | 13,4 % | 20 мар. 2023 г. |
30Наблюдать | CVE-2018-20410Эксплойта нет | WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow.wellintech · kingscada · CWE-787 | Высокая7,5 | — | 1,6 % | 23 дек. 2018 г. |
28Наблюдать | CVE-2012-1977Эксплойта нет | WellinTech KingSCADA Missing Encryption of Sensitive Datawellintech · kingview · CWE-311 | Высокая7,1 | — | 0,8 % | 9 мая 2012 г. |
27Наблюдать | CVE-2013-6127Proof of concept | The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly rewellintech · kingview · CWE-22 | Средняя5,8 | — | 13,9 % | 25 окт. 2013 г. |
26Наблюдать | CVE-2013-2826Эксплойта нет | WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager cwellintech · kingalarm\&event · CWE-264 | Средняя6,4 | — | 1,8 % | 15 янв. 2014 г. |
24Наблюдать | CVE-2013-6128Proof of concept | The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrwellintech · kingview · CWE-264 | Средняя5,8 | — | 2,6 % | 25 окт. 2013 г. |
21Наблюдать | CVE-2012-2560Эксплойта нет | Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to wellintech · kingview · CWE-22 | Средняя5,0 | — | 2,6 % | 4 июл. 2012 г. |
8Наблюдать | CVE-2012-4899Эксплойта нет | WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials wellintech · kingview · CWE-310 | Низкая2,1 | — | 0,3 % | 10 окт. 2012 г. |
- CVE-2012-471158В плане
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.e
КритическаяCVSS 10,0Готовый эксплойтEPSS 61 %wellintech · kingview15 февр. 2013 г.
- CVE-2011-314252В плане
Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute ar
КритическаяCVSS 10,0Proof of conceptEPSS 38 %wellintech · kingview16 авг. 2011 г.
- CVE-2011-040646В плане
Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long reques
КритическаяCVSS 10,0Proof of conceptEPSS 21 %wellintech · kingview10 янв. 2011 г.
- CVE-2012-183145В плане
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 55
КритическаяCVSS 10,0Proof of conceptEPSS 16 %wellintech · kingview4 июл. 2012 г.
- CVE-2013-282744В плане
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote
ВысокаяCVSS 7,5Готовый эксплойтEPSS 48 %wellintech · kingalarm\&event15 янв. 2014 г.
- CVE-2014-078744В плане
WellinTech KingSCADA Stack-based Buffer Overflow
КритическаяCVSS 10,0Proof of conceptEPSS 14 %wellintech · kingscada12 апр. 2014 г.
- CVE-2022-4366343В плане
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05.
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %wellintech · kinghistorian20 мар. 2023 г.
- CVE-2011-453643В плане
Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 all
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %wellintech · kingview27 дек. 2011 г.
- CVE-2012-183042В плане
Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5
КритическаяCVSS 10,0Proof of conceptEPSS 8 %wellintech · kingview4 июл. 2012 г.
- CVE-2012-183242В плане
WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted p
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %wellintech · kingview4 июл. 2012 г.
- CVE-2012-255941В плане
WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a cr
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %wellintech · kinghistorian4 июл. 2012 г.
- CVE-2012-181938Наблюдать
Untrusted search path vulnerability in WellinTech KingView 6.53 allows local users to gain privileges via a Trojan horse DLL in the current
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %wellintech · kingview2 мая 2012 г.
- CVE-2022-4512434Наблюдать
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05.
ВысокаяCVSS 7,5Эксплойта нетEPSS 13 %wellintech · kinghistorian20 мар. 2023 г.
- CVE-2018-2041030Наблюдать
WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %wellintech · kingscada23 дек. 2018 г.
- CVE-2012-197728Наблюдать
WellinTech KingSCADA Missing Encryption of Sensitive Data
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %wellintech · kingview9 мая 2012 г.
- CVE-2013-612727Наблюдать
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly re
СредняяCVSS 5,8Proof of conceptEPSS 14 %wellintech · kingview25 окт. 2013 г.
- CVE-2013-282626Наблюдать
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager c
СредняяCVSS 6,4Эксплойта нетEPSS 2 %wellintech · kingalarm\&event15 янв. 2014 г.
- CVE-2013-612824Наблюдать
The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restr
СредняяCVSS 5,8Proof of conceptEPSS 3 %wellintech · kingview25 окт. 2013 г.
- CVE-2012-256021Наблюдать
Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to
СредняяCVSS 5,0Эксплойта нетEPSS 3 %wellintech · kingview4 июл. 2012 г.
- CVE-2012-48998Наблюдать
WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %wellintech · kingview10 окт. 2012 г.