Schneider Electric
schneider-electric
771 CVEs • 1,745 products
Products (1,745)
Click to collapseToggle
Products (1,745)
Click to collapse
CVEs (771)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine wheth...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to...Show more |
The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email addre...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input param...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input p...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input pa...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input p...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the obje...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the ap...Show more |
1Schneider Electric 1U.motion Builder Nov 21, 2024 Jul 3, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability. |
5Canonical DebianProcps Ng Project+2 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 May 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. |
6Canonical DebianOpensuse+3 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 23, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs b...Show more |
12Arm CanonicalDebian+9 more282Atom C Atom EAtom X5 E3930+279 moreMay 29, 2026 May 22, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more |
1Schneider Electric 1Ampla Manufacturing Execution System Nov 21, 2024 May 18, 2018 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more |
1Schneider Electric 1Ampla Manufacturing Execution System Nov 21, 2024 May 18, 2018 N/A· v4 3.9 LOW· v3 1.9 LOW· v2 Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to...Show more |
2Aveva Schneider Electric2Clearscada ClearscadaNov 21, 2024 May 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the Cl...Show more |
1Schneider Electric 1Triconex Tricon Mp 3008 Firmware Nov 21, 2024 May 4, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could all...Show more |
1Schneider Electric 1Triconex Tricon Mp 3008 Firmware Nov 21, 2024 May 4, 2018 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to g...Show more |
6Canonical DebianHp+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreMay 6, 2025 Apr 19, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JR...Show more |
6Canonical DebianHp+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreNov 21, 2024 Apr 19, 2018 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to expl...Show more |