Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-32545

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Attacker Value
Unknown

CVE-2022-3377

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.
Attacker Value
Unknown

CVE-2022-3379

Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.
Attacker Value
Unknown

CVE-2022-3378

Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write.
Attacker Value
Unknown

CVE-2022-28690

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-30540

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code
Attacker Value
Unknown

CVE-2022-29488

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-27184

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-33015

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.
Attacker Value
Unknown

CVE-2021-32995

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute code in the context of the current process.