Vulnerabilities > Microsys > Promotic > 8.0.6

DATE CVE VULNERABILITY TITLE RISK
2013-05-23 CVE-2011-4520 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsys Promotic
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
network
microsys CWE-119
4.3
2013-05-23 CVE-2011-4519 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsys Promotic
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.
network
microsys CWE-119
4.3
2013-05-23 CVE-2011-4518 Path Traversal vulnerability in Microsys Promotic
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
microsys CWE-22
5.0
2012-04-13 CVE-2011-4874 Resource Management Errors vulnerability in Microsys Promotic
Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1.7 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (data corruption and application crash) via a crafted project (aka .pra) file.
7.9