Vulnerabilities (CVE)

Filtered by vendor Mz-automation Subscribe
Filtered by product Libiec61850
Total 29 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16510 1 Mz-automation 1 Libiec61850 2024-11-21 5.0 MEDIUM 7.5 HIGH
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.
CVE-2019-1010300 1 Mz-automation 1 Libiec61850 2024-11-21 5.0 MEDIUM 7.5 HIGH
mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet.
CVE-2018-19185 1 Mz-automation 1 Libiec61850 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.
CVE-2018-19122 1 Mz-automation 1 Libiec61850 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.
CVE-2018-19121 1 Mz-automation 1 Libiec61850 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.
CVE-2018-19093 1 Mz-automation 1 Libiec61850 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/client_control.c. NOTE: the software maintainer disputes this because it requires incorrect usage of the client_example_control program
CVE-2018-18957 1 Mz-automation 1 Libiec61850 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.
CVE-2018-18937 1 Mz-automation 1 Libiec61850 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.
CVE-2018-18834 1 Mz-automation 1 Libiec61850 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.