VARIoT IoT vulnerabilities database
| VAR-202103-0639 | CVE-2021-21515 | Dell EMC SourceOne Cross-site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server. Dell EMC SourceOne is an application software of Dell (Dell)
| VAR-202103-0049 | CVE-2020-11309 | plural Qualcomm Product Free Memory Usage Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202103-0046 | CVE-2020-11299 | plural Qualcomm Classic buffer overflow vulnerability in the product |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202103-0045 | CVE-2020-11290 | plural Qualcomm Product Free Memory Usage Vulnerability |
CVSS V2: 6.9 CVSS V3: 7.0 Severity: HIGH |
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202103-0041 | CVE-2020-11226 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to out-of-bounds reading and a vulnerability related to array index validation.Information may be obtained
| VAR-202103-0042 | CVE-2020-11227 | plural Qualcomm Product index validation vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to array index validation and a vulnerability related to out-of-bounds writes.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202103-0040 | CVE-2020-11222 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202103-0039 | CVE-2020-11221 | plural Qualcomm Information leakage vulnerabilities in products |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a vulnerability related to information leakage.Information may be obtained
| VAR-202103-0037 | CVE-2020-11218 | plural Qualcomm Product Reachable Assertion Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a reachable assertion vulnerability.Denial of service (DoS) It may be put into a state
| VAR-202103-0036 | CVE-2020-11199 | plural Qualcomm Information leakage vulnerabilities in products |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a vulnerability related to information leakage.Information may be obtained
| VAR-202103-0035 | CVE-2020-11192 | plural Qualcomm Out-of-bounds write vulnerabilities in the product |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to out-of-bounds writing.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202103-0034 | CVE-2020-11190 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202103-0032 | CVE-2020-11188 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202103-0030 | CVE-2020-11171 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202103-0029 | CVE-2020-11166 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202102-1607 | No CVE | A denial of service vulnerability exists in SIMATIC S7-PLCSM (CNVD-2021-05556) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens.
SIMATIC S7-PLCSM has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1608 | No CVE | A denial of service vulnerability exists in SIMATIC S7-PLCSM (CNVD-2021-05557) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens.
SIMATIC S7-PLCSM has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1611 | No CVE | EasyBuilder Pro has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
EasyBuilder Pro is a configuration software developed by Weilun.
EasyBuilder Pro has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1613 | No CVE | Binary vulnerability exists in SIMATIC S7-PLCSM |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens.
A binary vulnerability exists in SIMATIC S7-PLCSM, which can be exploited by an attacker to cause a denial of service.
| VAR-202102-1615 | No CVE | A denial of service vulnerability exists in SIMATIC S7-PLCSM |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens.
SIMATIC S7-PLCSM has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.