← Back

Xarrow

xarrow

7 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Xarrow
xarrow

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xarrow
1Xarrow
Jun 17, 2026
May 16, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
1Xarrow
1Xarrow
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
1Xarrow
1Xarrow
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.
1Xarrow
1Xarrow
Apr 29, 2026
May 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.
1Xarrow
1Xarrow
Apr 29, 2026
May 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation.
1Xarrow
1Xarrow
Apr 29, 2026
May 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.
1Xarrow
1Xarrow
Apr 29, 2026
May 25, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors.