Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via (1) a long username in an OnFCCONNECTFCSLOGIN packet, and crafted (2) OnFCCTAGLISTFCSCADDTAG, (3) OnFCCTAGLISTFCSCDELTAG, (4) OnFCCTAGLISTFCSADDTAGMS, (5) OnFCRFUSERFCSLOGIN, (6) unspecified "OnFCBINFILEFCSFILE", (7) OnFCCGETTAGFCSGETTELEMETRY, (8) OnFCCGETTAGFCSGETCHANNELTELEMETRY, (9) OnFCCGETTAGFCSSETTELEMETRY, (10) OnFCCGETTAGFCSSETCHANNELTELEMETRY, and (11) OnFCSCRIPTFCSSTARTPROG packets to port 910.
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) OnFCMISCFCSMSGBROADCAST and (2) OnFCMISCFCSMSGSEND packets, which trigger a heap-based buffer overflow.
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPCINITIALIZE, (2) SCPCINITIALIZERF, or (3) SCPCTXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests.
Multiple untrusted search path vulnerabilities in RealFlex RealWin before 2.1.13, FlexView before 3.1.86, and RealWinDemo before 2.1.13 allow local users to gain privileges via a Trojan horse (1) realwin.dll or (2) keyhook.dll file in the current working directory.
Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when registerglobals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.