Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-34263

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Fatek Automation FvDesigner FPJ File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of FPJ files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18162.
0
Attacker Value
Unknown

CVE-2023-34262

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of FPJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18161.
0
Attacker Value
Unknown

CVE-2022-2866

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a valid user is tricked into using maliciously crafted project files, an attacker could achieve arbitrary code execution.
Attacker Value
Unknown

CVE-2022-23985

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Attacker Value
Unknown

CVE-2022-25170

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code
Attacker Value
Unknown

CVE-2022-21209

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Attacker Value
Unknown

CVE-2021-32931

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
An uninitialized pointer in FATEK Automation FvDesigner, Versions 1.5.88 and prior may be exploited while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-32947

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-32939

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a project file that may permit arbitrary code execution.
Attacker Value
Unknown

CVE-2021-22683

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.