Show filters
44 Total Results
Displaying 11-20 of 44
Sort by:
Attacker Value
Unknown
CVE-2023-34263
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Fatek Automation FvDesigner FPJ File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of FPJ files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18162.
0
Attacker Value
Unknown
CVE-2023-34262
Disclosure Date: May 03, 2024 (last updated May 03, 2024)
Fatek Automation FvDesigner FPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of FPJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18161.
0
Attacker Value
Unknown
CVE-2022-2866
Disclosure Date: August 31, 2022 (last updated October 08, 2023)
FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a valid user is tricked into using maliciously crafted project files, an attacker could achieve arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-23985
Disclosure Date: February 22, 2022 (last updated October 07, 2023)
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-25170
Disclosure Date: February 22, 2022 (last updated October 07, 2023)
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code
0
Attacker Value
Unknown
CVE-2022-21209
Disclosure Date: February 22, 2022 (last updated October 07, 2023)
The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-43556
Disclosure Date: November 16, 2021 (last updated October 07, 2023)
FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-43554
Disclosure Date: November 16, 2021 (last updated October 07, 2023)
FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-38442
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a heap-corruption condition. An attacker could leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2021-38430
Disclosure Date: October 07, 2021 (last updated February 23, 2025)
FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files, which could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code.
0