
CVE-2012-4709
https://notcve.org/view.php?id=CVE-2012-4709
13 Oct 2013 — Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. Invensys Wonderware InTouch HMI 2012 R2 y anteriores permite a atacantes remotos leer archivos de forma arbitraria, enviar peticiones HTTP a servidores de intranet... • http://ics-cert.us-cert.gov/advisories/ICSA-13-276-01 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-4693
https://notcve.org/view.php?id=CVE-2012-4693
18 Dec 2012 — Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file. nvensys Wonderware InTouch R2 2012 y anteriores y ProcessSuite Siemens utilizan un algoritmo de cifrado débil para los datos en Ps_security.ini, lo que hace que sea más fácil para los usuarios locales descubrir contraseñas mediante la lectura de este archivo. • http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-370812.pdf • CWE-310: Cryptographic Issues •

CVE-2012-3005
https://notcve.org/view.php?id=CVE-2012-3005
26 Jul 2012 — Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. Una vulnerabilidad de ruta de búsqueda no confiable en Invensys Wonderware InTouch 2012 y anteriores, tal como se utiliza en el servidor de aplicaciones Wonderware, Wonderware Infor... • http://www.us-cert.gov/control_systems/pdf/ICSA-12-177-02.pdf •

CVE-2012-3847
https://notcve.org/view.php?id=CVE-2012-3847
05 Jul 2012 — slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause a denial of service (resource consumption) via a long Unicode string, a different vulnerability than CVE-2012-3007. slssvc.exe en Invensys Wonderware SuiteLink en Invensys InTouch 2012 y Wonderware Application Server 2012, permite a atacantes remotos causar una denegación de servicio (consumo de recursos) a través de una larga cadena Unicode, una vulnerabilidad diferen... • http://secunia.com/advisories/49173 • CWE-399: Resource Management Errors •

CVE-2012-3007
https://notcve.org/view.php?id=CVE-2012-3007
05 Jul 2012 — Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and other products, allows remote attackers to cause a denial of service (daemon crash or hang) via a long Unicode string. Desbordamiento de buffer basado en pila en slssvc.exe antes de v58.x en Inven... • http://secunia.com/advisories/49173 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-0257
https://notcve.org/view.php?id=CVE-2012-0257
02 Apr 2012 — Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite. Desbordamie... • http://osvdb.org/80891 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-0258
https://notcve.org/view.php?id=CVE-2012-0258
02 Apr 2012 — Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member. Desbordamiento de búfer basado en memoria dinámic... • http://osvdb.org/80891 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •