CVE-2019-12265
- EPSS 4.59%
- Veröffentlicht 09.08.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:31
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
CVE-2019-12263
- EPSS 1.44%
- Veröffentlicht 09.08.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:31
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
CVE-2019-12259
- EPSS 9.76%
- Veröffentlicht 09.08.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:30
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.
CVE-2019-12257
- EPSS 15.36%
- Veröffentlicht 09.08.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:30
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
CVE-2019-12256
- EPSS 8.2%
- Veröffentlicht 09.08.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:29
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
CVE-2019-12264
- EPSS 0.25%
- Veröffentlicht 05.08.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:31
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.
CVE-2019-9865
- EPSS 1.77%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:28
When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memory copy. It may allow remote attackers to cause a denial of service (crash) or possibly exec...
CVE-2015-7599
- EPSS 5.29%
- Veröffentlicht 07.02.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitra...
CVE-2015-3963
- EPSS 4.71%
- Veröffentlicht 04.08.2015 01:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly genera...
- EPSS 0.68%
- Veröffentlicht 20.03.2013 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.