Show filters
107 Total Results
Displaying 1-10 of 107
Sort by:
Attacker Value
Unknown
CVE-2025-22880
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-13061
Disclosure Date: December 31, 2024 (last updated January 02, 2025)
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.
0
Attacker Value
Unknown
CVE-2024-12836
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22450.
0
Attacker Value
Unknown
CVE-2024-12835
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of ICS files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22415.
0
Attacker Value
Unknown
CVE-2024-12834
Disclosure Date: December 30, 2024 (last updated January 02, 2025)
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22414.
0
Attacker Value
Unknown
CVE-2024-12677
Disclosure Date: December 20, 2024 (last updated December 21, 2024)
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-38658
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
0
Attacker Value
Unknown
CVE-2024-38389
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
0
Attacker Value
Unknown
CVE-2024-38309
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
There are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier), TELLUS (v4.0.19.0 and earlier), and TELLUS Lite (v4.0.19.0 and earlier).
If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.
0
Attacker Value
Unknown
CVE-2024-10456
Disclosure Date: October 30, 2024 (last updated October 31, 2024)
Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication.
0