Known vulnerabilities in Advantech WebAccess 8.1_20160519 - page 4

Version: 8.1_20160519
Software CPE: cpe:2.3:a:advantech:advantech_webaccess:*:*:*:*:*:*:*:*
Total vulnerabilities: 74
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Advantech WebAccess version 8.1_20160519 Advantech WebAccess 8.1_20160519 is affected by 74 vulnerabilities: 55 high, 3 medium, 16 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU9113 - Untrusted Pointer Dereference
CVE-2017-12719
CWE-822 High
No
No
- 03.11.2017 SB2017110305
#VU9112 - Stack-based buffer overflow
CVE-2017-14016
CWE-121 High
Public exploit available
No
- 03.11.2017 SB2017110305
#VU8044 - Incorrect Permission Assignment for Critical Resource
CVE-2017-12713
CWE-732 Low
No
No
- 30.08.2017 SB2017083003
#VU8043 - Incorrect Privilege Assignment
CVE-2017-12711
CWE-266 Low
No
No
- 30.08.2017 SB2017083003
#VU8042 - Untrusted Search Path
CVE-2017-12717
CWE-426 Low
No
No
- 30.08.2017 SB2017083003
#VU8041 - Improper Authentication
CVE-2017-12698
CWE-287 High
No
No
- 30.08.2017 SB2017083003
#VU8040 - Use of Externally-Controlled Format String
CVE-2017-12702
CWE-134 High
No
No
- 30.08.2017 SB2017083003
#VU8039 - Heap-based Buffer Overflow
CVE-2017-12704
CWE-122 High
No
No
- 30.08.2017 SB2017083003
#VU8038 - Stack-based buffer overflow
CVE-2017-12706
CWE-121 High
No
No
- 30.08.2017 SB2017083003
#VU8037 - Memory corruption
CVE-2017-12708
CWE-119 High
No
No
- 30.08.2017 SB2017083003
#VU8036 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-12710
CWE-89 Low
No
No
- 30.08.2017 SB2017083003
#VU5824 - Uncontrolled Search Path Element
CVE-2017-5175
CWE-427 High
No
No
- 14.02.2017 SB2017021405
#VU4566 - Improper Authentication
CVE-2017-5152
CWE-287 Medium
No
No
- 12.01.2017 SB2017011301
#VU4565 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-5154
CWE-89 Medium
No
No
- 12.01.2017 SB2017011301


Showing elements 61 - 80 out of 74