CVE Vulnerability Database

Search and browse 284 known security vulnerabilities. Filter by severity, vendor, product, and year.

284 vulnerabilities found
CVE-2020-6986
7.5 high

In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.

Omron Plc Cj1 Firmware Mar 5, 2020
CVE-2019-6857
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service of the controller when reading specific memory blocks using Mod

Schneider-Electric Modicon M580 Firmware Jan 6, 2020
CVE-2019-6856
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP.

Schneider-Electric Modicon M580 Firmware Jan 6, 2020
CVE-2018-7794
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP.

Schneider-Electric Modicon M580 Firmware Jan 6, 2020
CVE-2019-17571
9.8 critical

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2

Apache Log4J Dec 20, 2019
CVE-2019-18269
9.8 critical

Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.

Omron Plc Cj Firmware Dec 16, 2019
CVE-2019-13533
8.1 high

In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

Omron Plc Cj Firmware Dec 16, 2019
CVE-2019-19378
7.8 high

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.

Linux Linux Kernel Nov 29, 2019
CVE-2019-13721
8.8 high

Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Google Chrome Nov 25, 2019
CVE-2019-6852
7.5 high

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP har

Schneider-Electric Bmx P34X Firmware Nov 20, 2019
CVE-2019-11135
6.5 medium

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

Opensuse Leap Nov 14, 2019
CVE-2019-14360
4.6 medium

On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be

Hyundai-Pay Kasse Hk-1000 Firmware Nov 2, 2019
CVE-2019-18197
7.5 high

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo

Xmlsoft Libxslt Oct 18, 2019
CVE-2019-16910
5.3 medium

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix i

Arm Mbed Crypto Sep 26, 2019
CVE-2019-10996
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that can reference memory after it has been freed.

Redlion Crimson Sep 23, 2019
CVE-2019-10990
6.5 medium

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.

Redlion Crimson Sep 23, 2019
CVE-2019-10984
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that causes the program to mishandle pointers.

Redlion Crimson Sep 23, 2019
CVE-2019-10978
7.8 high

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilities to be exploited when a valid user opens a specially crafted, malicious input file that operates outside of the designated memory area.

Redlion Crimson Sep 23, 2019
CVE-2019-6829
7.5 high

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

Schneider-Electric Modicon M580 Firmware Sep 17, 2019
CVE-2019-16230
4.7 medium

drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics car

Linux Linux Kernel Sep 11, 2019
CVE-2019-16168
6.5 medium

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Sqlite Sqlite Sep 9, 2019
CVE-2019-15213
4.6 medium

An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.

Linux Linux Kernel Aug 19, 2019
CVE-2019-1010292
9.8 critical

Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is: optee_os. The fixed version is: v3.4.0.

Trustedfirmware Op-Tee Jul 16, 2019
CVE-2019-1010298
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019