← Back
CWE-767

4 CVEs • Abstraction: Base

Access to Critical Private Variable via Public Method

The product defines a public method that reads or modifies a private variable.

JSON object

Loading...

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zabbix
1Zabbix
Jun 17, 2026
Nov 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.
-
-
Jun 17, 2026
Nov 26, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-tex...Show more
The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].Show less
3Arcinfo
ArcinformatiquePcvuesolutions
3Pcvue
PcvuePcvue
Jul 9, 2026
Oct 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This...Show more
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.Show less
1Phoenixcontact
1Ilc Plcs Firmware
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.