CVE Vulnerability Database

Search and browse 284 known security vulnerabilities. Filter by severity, vendor, product, and year.

284 vulnerabilities found
CVE-2019-10955
6.1 medium

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (inclu

Rockwellautomation Micrologix 1400 A Firmware Apr 25, 2019
CVE-2019-10953
7.5 high

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Abb Pm554-Tp-Eth Firmware Apr 17, 2019
CVE-2019-6575
7.5 high

A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4

Siemens Simatic Cp443-1 Opc Ua Firmware Apr 17, 2019
CVE-2018-16561
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart. Successful exploitation requires an

Siemens Simatic S7-300 Firmware Apr 17, 2019
CVE-2019-11068
9.8 critical

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Xmlsoft Libxslt Apr 10, 2019
CVE-2019-7386
6.5 medium

A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code executio

Kaiostech Kaios Mar 21, 2019
CVE-2019-9201
9.8 critical

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

Phoenixcontact Ilc 131 Eth Firmware Feb 26, 2019
CVE-2019-7317
5.3 medium

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Libpng Libpng Feb 4, 2019
CVE-2019-6109
6.8 medium

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This af

Openbsd Openssh Jan 31, 2019
CVE-2018-19440
5.3 medium

ARM Trusted Firmware-A allows information disclosure.

Trustedfirmware Trusted Firmware-A Jan 30, 2019
CVE-2019-6129
6.5 medium

png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

Libpng Libpng Jan 11, 2019
CVE-2017-15031
7.5 high

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.

Trustedfirmware Trusted Firmware-A Dec 18, 2018
CVE-2018-17924
8.6 high

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in

Rockwellautomation Micrologix 1400 Firmware Dec 7, 2018
CVE-2018-19608
4.7 medium

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

Arm Mbed Tls Dec 5, 2018
CVE-2018-6439
7.8 high

A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.

Broadcom Fabric Operating System Dec 3, 2018
CVE-2018-7798
8.2 high

A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.

Schneider-Electric Somachine Basic Nov 2, 2018
CVE-2018-7792
7.5 high

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-7791
9.8 critical

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-7790
9.8 critical

An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Mo

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-7795
5.4 medium

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.

Schneider-Electric Powerlogic Pm5560 Firmware Aug 29, 2018
CVE-2018-7789
7.5 high

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-3646
5.6 medium

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.

Intel Core I3 Aug 14, 2018
CVE-2018-3620
5.6 medium

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

Intel Core I3 Aug 14, 2018
CVE-2018-3615
7.3 high

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

Intel Core I3 Aug 14, 2018