Vulnerabilities > Medicomp

DATE CVE VULNERABILITY TITLE RISK
2015-10-29 CVE-2015-6006 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Medicomp Medcin Engine 2.22.20153.223
The AddUserFinding implementation in Medicomp MEDCIN Engine 2.22.20153.x before 2.22.20153.226 might allow remote attackers to execute arbitrary code or cause a denial of service (integer truncation and heap-based buffer overflow) via a crafted packet on port 8190.
network
low complexity
medicomp CWE-119
7.5
2015-10-29 CVE-2015-2901 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Medicomp Medcin Engine 2.22.20142.166
Multiple stack-based buffer overflows in Medicomp MEDCIN Engine 2.22.20142.166 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the GetProperty info_getproperty function and (2) the GetProperty UdfCodeList function.
network
medicomp CWE-119
6.8
2015-10-29 CVE-2015-2900 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Medicomp Medcin Engine
The AddUserFinding add_userfinding2 function in Medicomp MEDCIN Engine before 2.22.20153.226 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted packet on port 8190.
network
medicomp CWE-119
6.8
2015-10-29 CVE-2015-2899 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Medicomp Medcin Engine
Heap-based buffer overflow in the QualifierList retrieve_qualifier_list function in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a long list name in a packet on port 8190.
network
medicomp CWE-119
6.8
2015-10-29 CVE-2015-2898 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Medicomp Medcin Engine
Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to (1) the SetGroupSequenceEx na_setgroupsequenceex function, (2) the FormatDate julptostr function, and (3) the UserFindingCodes addtocl function.
network
medicomp CWE-119
6.8