Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown
CVE-2023-7206
Disclosure Date: January 15, 2024 (last updated February 26, 2025)
In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
0
Attacker Value
Unknown
CVE-2023-32203
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-31278
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-31244
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
0
Attacker Value
Unknown
CVE-2023-29503
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-28653
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-27916
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-32539
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e3c04. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-32289
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2023-32281
Disclosure Date: June 06, 2023 (last updated February 25, 2025)
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
0