|
190661
|
3.3 |
LOW
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder versions 3.30 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to read unauthorized information.
|
-
|
CVE-2021-38440
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190662
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid user opens a malformed project file, which may allow arbitrary code execution.
|
-
|
CVE-2021-38438
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190663
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a memory-corruption condition. An attacker could …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-38436
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190664
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an unexpected sign extension. An attacker could l…
|
-
|
CVE-2021-38434
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190665
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files, which could result in a stack-based buffer overflow. An attacker could levera…
|
-
|
CVE-2021-38430
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190666
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an out-of-bounds write. An attacker could leverag…
|
-
|
CVE-2021-38426
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190667
|
7.5 |
HIGH
Network
|
bestpractical fedoraproject debian
|
request_tracker fedora debian_linux
|
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-38562
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190668
|
9.8 |
CRITICAL
Network
|
fatek
|
communication_server_firmware
|
FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow an attacker to rem…
|
-
|
CVE-2021-38432
|
2024-11-21 15:17 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190669
|
4.3 |
MEDIUM
Network
|
advantech
|
webaccess_scada
|
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.
|
CWE-862
Missing Authorization
|
CVE-2021-38431
|
2024-11-21 15:17 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190670
|
8.0 |
HIGH
Adjacent
|
microsoft
|
windows_11 windows_server_2022
|
Windows Hyper-V Remote Code Execution Vulnerability
|
NVD-CWE-noinfo
|
CVE-2021-38672
|
2024-11-21 15:17 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|