CVE-2016-5810
- EPSS 25.4%
- Published 02.05.2017 14:59:00
- Last modified 20.04.2025 01:37:25
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.
CVE-2017-5152
- EPSS 1.31%
- Published 13.02.2017 21:59:02
- Last modified 20.04.2025 01:37:25
An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICATION BYPASS).
CVE-2017-5154
- EPSS 0.53%
- Published 13.02.2017 21:59:02
- Last modified 20.04.2025 01:37:25
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the appli...
- EPSS 0.14%
- Published 25.06.2016 01:59:02
- Last modified 12.04.2025 10:46:40
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.
CVE-2016-4525
- EPSS 0.19%
- Published 25.06.2016 01:59:01
- Last modified 12.04.2025 10:46:40
Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) fl...
- EPSS 1.79%
- Published 15.01.2016 03:59:21
- Last modified 12.04.2025 10:46:40
Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted RPC request.
- EPSS 1.28%
- Published 15.01.2016 03:59:21
- Last modified 12.04.2025 10:46:40
Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC request.
CVE-2016-0858
- EPSS 1.15%
- Published 15.01.2016 03:59:20
- Last modified 12.04.2025 10:46:40
Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.
- EPSS 8.21%
- Published 15.01.2016 03:59:19
- Last modified 12.04.2025 10:46:40
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.
- EPSS 60.94%
- Published 15.01.2016 03:59:18
- Last modified 12.04.2025 10:46:40
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.