Filtered by vendor Mz-automation Subscriptions
Filtered by product Libiec61850 Subscriptions
Total 29 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-19930 1 Mz-automation 1 Libiec61850 2019-12-30 6.5 Medium
In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.
CVE-2019-19931 1 Mz-automation 1 Libiec61850 2019-12-30 8.8 High
In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.
CVE-2019-19944 1 Mz-automation 1 Libiec61850 2019-12-30 6.5 Medium
In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.
CVE-2019-16510 1 Mz-automation 1 Libiec61850 2019-09-19 7.5 High
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.
CVE-2019-1010300 1 Mz-automation 1 Libiec61850 2019-07-22 N/A
mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet.
CVE-2019-6719 1 Mz-automation 1 Libiec61850 2019-02-07 N/A
An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_server.c, as demonstrated by examples/server_example_goose/server_example_goose.c and examples/server_example_61400_25/server_example_61400_25.c.
CVE-2018-18937 1 Mz-automation 1 Libiec61850 2018-12-07 N/A
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.
CVE-2018-19122 1 Mz-automation 1 Libiec61850 2018-12-07 N/A
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.
CVE-2018-19121 1 Mz-automation 1 Libiec61850 2018-12-07 N/A
An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.