CVE-2026-82623
- EPSS 0.41%
- Veröffentlicht 31.08.2026 06:15:08
- Zuletzt bearbeitet 31.08.2026 20:56:08
A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History Backend. The manipulation r...
CVE-2026-67870
- EPSS 0.27%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targ...
CVE-2026-67869
- EPSS 0.47%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
CVE-2026-67863
- EPSS 0.41%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem f...
CVE-2026-67864
- EPSS 0.25%
- Veröffentlicht 05.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
CVE-2026-67861
- EPSS 0.42%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:04:16
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
CVE-2026-67862
- EPSS 0.21%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.
CVE-2026-67860
- EPSS 0.14%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.
CVE-2026-67859
- EPSS 0.47%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 18:04:16
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
CVE-2026-67858
- EPSS 0.49%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:11
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request...