Vulnerabilities > Softing > Uatoolkit Embedded > 1.40

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2022-44018 NULL Pointer Dereference vulnerability in Softing Uatoolkit Embedded 1.31/1.40
In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application.
network
low complexity
softing CWE-476
7.5
2023-01-26 CVE-2022-45920 Memory Leak vulnerability in Softing Uatoolkit Embedded 1.31/1.40
In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak.
network
low complexity
softing CWE-401
7.5