threat
engine
.sh
Back
·
··:··
Home
/
Product
/
siemens simatic itc2200 pro firmware
Product
siemens simatic itc2200 pro firmware
19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2017-18922
>= 3.0.0.0 and < 3.2.1.0
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious
9.8
CRITICAL
CVE-2020-14405
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
6.5
MEDIUM
CVE-2020-14404
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
5.4
MEDIUM
CVE-2020-14403
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
5.4
MEDIUM
CVE-2020-14402
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
5.4
MEDIUM
CVE-2020-14401
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
6.5
MEDIUM
CVE-2020-14398
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient
7.5
HIGH
CVE-2020-14397
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
7.5
HIGH
CVE-2020-14396
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
7.5
HIGH
CVE-2019-20840
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses
7.5
HIGH
CVE-2019-20839
>= 3.0.0.0 and < 3.2.1.0
libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
7.5
HIGH
CVE-2018-21247
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libv
7.5
HIGH
CVE-2019-20788
>= 3.0.0.0 and < 3.2.1.0
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a
9.8
CRITICAL
CVE-2019-15681
>= 3.0.0.0 and < 3.2.1.0
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an
7.5
HIGH
CVE-2018-20750
>= 3.0.0.0 and < 3.2.1.0
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 wa
9.8
CRITICAL
CVE-2018-20749
>= 3.0.0.0 and < 3.2.1.0
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was
9.8
CRITICAL
CVE-2018-20748
>= 3.0.0.0 and < 3.2.1.0
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-2
9.8
CRITICAL
CVE-2018-20019
>= 3.0.0.0 and < 3.2.1.0
LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC cli
9.8
CRITICAL
CVE-2017-5753
< 3.1
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informatio
5.6
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin