CVE-2017-14016
- EPSS 16.04%
- Veröffentlicht 06.11.2017 22:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an a...
CVE-2017-12717
- EPSS 2.44%
- Veröffentlicht 30.08.2017 18:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the applicat...
CVE-2017-12698
- EPSS 4.83%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.
CVE-2017-12702
- EPSS 2.29%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute arbitrary c...
CVE-2017-12704
- EPSS 2.6%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to cop...
CVE-2017-12706
- EPSS 3.17%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to co...
- EPSS 3.39%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities that allow invalid locations to be referenced...
CVE-2017-12710
- EPSS 2.21%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.
CVE-2017-12711
- EPSS 0.35%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.
CVE-2017-12713
- EPSS 0.35%
- Veröffentlicht 30.08.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator account...