Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2025-0591

Disclosure Date: February 17, 2025 (last updated February 17, 2025)
Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.
0
Attacker Value
Unknown

CVE-2024-31413

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver. 1.56 or lower, and was updated through Sysmac Studio V1 auto update in January 2024 or prior). Opening a specially crafted project file may lead to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2022-21137

Disclosure Date: January 06, 2022 (last updated October 07, 2023)
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-27413

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2020-27259

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2020-27261

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2020-27257

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.
Attacker Value
Unknown

CVE-2018-19027

Disclosure Date: January 30, 2019 (last updated November 27, 2024)
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
0
Attacker Value
Unknown

CVE-2018-18993

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior). When processing project files, the application allows input data to exceed the buffer. An attacker could use a specially crafted project file to overflow the buffer and execute code under the privileges of the application.
Attacker Value
Unknown

CVE-2018-18989

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
0