Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-7769 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-89
8.8
2018-07-03 CVE-2018-7768 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-89
8.8
2018-07-03 CVE-2018-7767 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-89
8.8
2018-07-03 CVE-2018-7766 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-89
8.8
2018-07-03 CVE-2018-7765 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-89
8.8
2018-07-03 CVE-2018-7764 Path Traversal vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-22
4.3
2018-07-03 CVE-2018-7763 Path Traversal vulnerability in Schneider-Electric U.Motion Builder 1.2.1
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
network
low complexity
schneider-electric CWE-22
4.3
2018-05-23 CVE-2018-1126 Integer Overflow or Wraparound vulnerability in multiple products
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues.
9.8
2018-05-23 CVE-2018-1124 Integer Overflow or Wraparound vulnerability in multiple products
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function.
7.8
2018-05-22 CVE-2018-3639 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
5.5