Vulnerabilities > Xarrow > Xarrow

DATE CVE VULNERABILITY TITLE RISK
2022-05-16 CVE-2021-33001 Cross-site Scripting vulnerability in Xarrow 7.2
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.
network
xarrow CWE-79
4.3
2022-05-16 CVE-2021-33021 Cross-site Scripting vulnerability in Xarrow 7.2
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
network
xarrow CWE-79
4.3
2022-05-16 CVE-2021-33025 Improper Input Validation vulnerability in Xarrow 7.2
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
local
low complexity
xarrow CWE-20
4.6
2012-05-25 CVE-2012-2429 Numeric Errors vulnerability in Xarrow
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
xarrow CWE-189
critical
10.0
2012-05-25 CVE-2012-2428 Numeric Errors vulnerability in Xarrow
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation.
network
low complexity
xarrow CWE-189
critical
10.0
2012-05-25 CVE-2012-2427 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xarrow
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.
network
low complexity
xarrow CWE-119
critical
10.0
2012-05-25 CVE-2012-2426 Resource Management Errors vulnerability in Xarrow
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors.
network
low complexity
xarrow CWE-399
7.8