RSS   Vulnerabilities for 'Wonderware application server'   RSS

2012-07-04
 
CVE-2012-3847

CWE-399
 

 
slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause a denial of service (resource consumption) via a long Unicode string, a different vulnerability than CVE-2012-3007.

 
 
CVE-2012-3007

CWE-119
 

 
Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and other products, allows remote attackers to cause a denial of service (daemon crash or hang) via a long Unicode string.

 
2012-04-02
 
CVE-2012-0258

CWE-119
 

 
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member.

 
 
CVE-2012-0257

CWE-119
 

 
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.

 
2010-08-05
 
CVE-2010-2974

CWE-119
 

 
Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated Engineering Environment (IEE), allows remote attackers to execute arbitrary code via the first argument to the UnsubscribeData method.

 

 >>> Vendor: Invensys 20 Products
Wonderware application server
Wonderware archestra configuration access component activex control
Foxboro i/a series batch
Wonderware inbatch
Wonderware information server
Wonderware hmi reports
Archestra application object toolkit
Foxboro control software
Infusion control edition
Infusion foundation edition
Infusion scada
Intouch
Dasabcip
Daserver runtime components
Dassidirect
Intouch/wonderware application server
Infusion ce/fe/scada
Wonderware historian
Wonderware intouch
Wonderware win-xml exporter


Copyright 2022, cxsecurity.com

 

Back to Top