Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.
2011-08-16T21:55:01.350
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | aveva | clearscada | 2005 | Yes |
| Application | aveva | clearscada | 2007 | Yes |
| Application | aveva | clearscada | 2009 | Yes |
| Application | schneider-electric | scx_67 | < r4.5 | Yes |
| Application | schneider-electric | scx_68 | < r3.9 | Yes |