Tibco Enterprise Message Service vulnerabilities

9 known vulnerabilities affecting tibco/enterprise_message_service.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH5

Vulnerabilities

Page 1 of 1
CVE-2021-28821HIGHCVSS 7.8≤ 8.5.12021-03-23
CVE-2021-28821 [HIGH] CWE-863 CVE-2021-28821: The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to in
nvd
CVE-2021-28822HIGHCVSS 7.8≤ 8.5.12021-03-23
CVE-2021-28822 [HIGH] CWE-427 CVE-2021-28822: The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration ( The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TI
nvd
CVE-2018-12415HIGHCVSS 8.8≤ 8.4.02018-11-06
CVE-2018-12415 [HIGH] CWE-352 CVE-2018-12415: The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Messag The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TI
nvd
CVE-2016-3628HIGHCVSS 8.8≤ 8.2.22016-04-20
CVE-2016-3628 [HIGH] CWE-119 CVE-2016-3628: Buffer overflow in tibemsd in the server in TIBCO Enterprise Message Service (EMS) before 8.3.0 and Buffer overflow in tibemsd in the server in TIBCO Enterprise Message Service (EMS) before 8.3.0 and EMS Appliance before 2.4.0 allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via crafted inbound data.
nvd
CVE-2011-0649HIGHCVSS 7.2v5.1.0v5.1.1+1 more2011-02-04
CVE-2011-0649 [HIGH] CVE-2011-0649: Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Ser Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknow
nvd
CVE-2009-1291CRITICALCVSS 10.0≤ 5.1.1v4.0.0+5 more2009-04-30
CVE-2009-1291 [CRITICAL] CWE-119 CVE-2009-1291: Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTw Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and components, EMS Server (aka tibems
nvd
CVE-2008-1704CRITICALCVSS 10.0≤ 4.4.2v4.0.0+5 more2008-04-11
CVE-2008-1704 [CRITICAL] CWE-119 CVE-2008-1704: Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProc Multiple buffer overflows in TIBCO Software Enterprise Message Service (EMS) before 4.4.3, and iProcess Engine 10.6.0 through 10.6.1, allow remote attackers to execute arbitrary code via a crafted message to the EMS server.
nvd
CVE-2007-5656CRITICALCVSS 10.0v4.0.0v4.1.0+4 more2008-01-16
CVE-2007-5656 [CRITICAL] CWE-399 CVE-2007-5656: TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory.
nvd
CVE-2007-5658CRITICALCVSS 10.0v4.0.0v4.1.0+4 more2008-01-16
CVE-2007-5658 [CRITICAL] CWE-20 CVE-2007-5658: Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, a Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow.
nvd