xArrow kayıtları
xarrow üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2012-2428İstismar yok | Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers axarrow · xarrow · CWE-189 | Kritik10,0 | — | %4,5 | 25 May 2012 |
41Planlayın | CVE-2012-2427İstismar yok | Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger axarrow · xarrow · CWE-119 | Kritik10,0 | — | %3,9 | 25 May 2012 |
41Planlayın | CVE-2012-2429İstismar yok | The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecifiexarrow · xarrow · CWE-189 | Kritik10,0 | — | %3,8 | 25 May 2012 |
32İzleyin | CVE-2012-2426İstismar yok | The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointexarrow · xarrow · CWE-399 | Yüksek7,8 | — | %2,2 | 25 May 2012 |
31İzleyin | CVE-2021-33025İstismar yok | xArrow SCADA Path Traversalxarrow · xarrow · CWE-79 | Yüksek7,8 | — | %0,3 | 16 May 2022 |
24İzleyin | CVE-2021-33001İstismar yok | xArrow SCADA Cross-site Scriptingxarrow · xarrow · CWE-79 | Orta6,1 | — | %0,8 | 16 May 2022 |
24İzleyin | CVE-2021-33021İstismar yok | xArrow SCADA Cross-site Scriptingxarrow · xarrow · CWE-79 | Orta6,1 | — | %0,8 | 16 May 2022 |
- CVE-2012-242841Planlayın
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers a
KritikCVSS 10,0İstismar yokEPSS %5xarrow · xarrow25 May 2012
- CVE-2012-242741Planlayın
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger a
KritikCVSS 10,0İstismar yokEPSS %4xarrow · xarrow25 May 2012
- CVE-2012-242941Planlayın
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecifie
KritikCVSS 10,0İstismar yokEPSS %4xarrow · xarrow25 May 2012
- CVE-2012-242632İzleyin
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointe
YüksekCVSS 7,8İstismar yokEPSS %2xarrow · xarrow25 May 2012
- CVE-2021-3302531İzleyin
xArrow SCADA Path Traversal
YüksekCVSS 7,8İstismar yokEPSS %0xarrow · xarrow16 May 2022
- CVE-2021-3300124İzleyin
xArrow SCADA Cross-site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1xarrow · xarrow16 May 2022
- CVE-2021-3302124İzleyin
xArrow SCADA Cross-site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1xarrow · xarrow16 May 2022