VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202103-0639 CVE-2021-21515 Dell EMC SourceOne  Cross-site Scripting Vulnerability CVSS V2: 3.5
CVSS V3: 5.4
Severity: MEDIUM
Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privileged attacker may potentially exploit this vulnerability, to hijack user sessions or to trick a victim application user to unknowingly send arbitrary requests to the server. Dell EMC SourceOne is an application software of Dell (Dell)
VAR-202103-0049 CVE-2020-11309 plural  Qualcomm  Product Free Memory Usage Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
Use after free in GPU driver while mapping the user memory to GPU memory due to improper check of referenced memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0046 CVE-2020-11299 plural  Qualcomm  Classic buffer overflow vulnerability in the product CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0045 CVE-2020-11290 plural  Qualcomm  Product Free Memory Usage Vulnerability CVSS V2: 6.9
CVSS V3: 7.0
Severity: HIGH
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0041 CVE-2020-11226 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to out-of-bounds reading and a vulnerability related to array index validation.Information may be obtained
VAR-202103-0042 CVE-2020-11227 plural  Qualcomm  Product index validation vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to array index validation and a vulnerability related to out-of-bounds writes.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0040 CVE-2020-11222 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
VAR-202103-0039 CVE-2020-11221 plural  Qualcomm  Information leakage vulnerabilities in products CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a vulnerability related to information leakage.Information may be obtained
VAR-202103-0037 CVE-2020-11218 plural  Qualcomm  Product Reachable Assertion Vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a reachable assertion vulnerability.Denial of service (DoS) It may be put into a state
VAR-202103-0036 CVE-2020-11199 plural  Qualcomm  Information leakage vulnerabilities in products CVSS V2: 2.1
CVSS V3: 5.5
Severity: MEDIUM
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a vulnerability related to information leakage.Information may be obtained
VAR-202103-0035 CVE-2020-11192 plural  Qualcomm  Out-of-bounds write vulnerabilities in the product CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to out-of-bounds writing.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202103-0034 CVE-2020-11190 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
VAR-202103-0032 CVE-2020-11188 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
VAR-202103-0030 CVE-2020-11171 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
VAR-202103-0029 CVE-2020-11166 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
VAR-202102-1607 No CVE A denial of service vulnerability exists in SIMATIC S7-PLCSM (CNVD-2021-05556) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens. SIMATIC S7-PLCSM has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1608 No CVE A denial of service vulnerability exists in SIMATIC S7-PLCSM (CNVD-2021-05557) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens. SIMATIC S7-PLCSM has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1611 No CVE EasyBuilder Pro has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
EasyBuilder Pro is a configuration software developed by Weilun. EasyBuilder Pro has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1613 No CVE Binary vulnerability exists in SIMATIC S7-PLCSM CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens. A binary vulnerability exists in SIMATIC S7-PLCSM, which can be exploited by an attacker to cause a denial of service.
VAR-202102-1615 No CVE A denial of service vulnerability exists in SIMATIC S7-PLCSM CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
SIMATIC S7-PLCSM is a PLC simulation software developed by Siemens. SIMATIC S7-PLCSM has a denial of service vulnerability, which can be exploited by an attacker to cause a denial of service.