Wind River VxWorks 6.9.4.11

CPE Details

Wind River VxWorks 6.9.4.11
6.9.4.11
2020-05-28
16h10 +00:00
2020-05-28
16h10 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:windriver:vxworks:6.9.4.11:*:*:*:*:*:*:*

Informations

Vendor

windriver

Product

vxworks

Version

6.9.4.11

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-38767 2022-11-24 23h00 +00:00 An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.
7.5
High
CVE-2021-43268 2021-11-24 15h15 +00:00 An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.
6.5
Medium
CVE-2020-35198 2021-05-12 08h55 +00:00 An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
9.8
Critical
CVE-2016-20009 2021-03-11 20h39 +00:00 A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
9.8
Critical
CVE-2020-28895 2021-02-03 14h16 +00:00 In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
7.3
High
CVE-2020-11440 2020-07-23 11h59 +00:00 httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.
7.5
High
CVE-2019-12261 2019-08-09 18h27 +00:00 Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
9.8
Critical
CVE-2019-12260 2019-08-09 18h18 +00:00 Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
9.8
Critical
CVE-2019-12258 2019-08-09 18h00 +00:00 Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
7.5
High
CVE-2019-12265 2019-08-09 16h14 +00:00 Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
5.3
Medium
CVE-2019-12263 2019-08-09 16h10 +00:00 Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
8.1
High
CVE-2019-12259 2019-08-09 16h05 +00:00 Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.
7.5
High
CVE-2019-12256 2019-08-09 15h57 +00:00 Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
9.8
Critical
CVE-2010-2965 2010-08-04 21h00 +00:00 The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.
10