Vulnerabilities > Fatek

DATE CVE VULNERABILITY TITLE RISK
2021-10-18 CVE-2021-38438 Use After Free vulnerability in Fatek Winproladder 3.28/3.30
A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid user opens a malformed project file, which may allow arbitrary code execution.
local
low complexity
fatek CWE-416
7.8
2021-10-18 CVE-2021-38440 Out-of-bounds Read vulnerability in Fatek Winproladder 3.28/3.30
FATEK Automation WinProladder versions 3.30 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to read unauthorized information.
local
low complexity
fatek CWE-125
3.3
2021-10-18 CVE-2021-38442 Out-of-bounds Write vulnerability in Fatek Winproladder 3.28/3.30
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a heap-corruption condition.
local
low complexity
fatek CWE-787
7.8
2021-10-15 CVE-2021-38432 Stack-based Buffer Overflow vulnerability in Fatek Communication Server Firmware
FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow an attacker to remotely execute code.
network
low complexity
fatek CWE-121
critical
9.8
2021-08-11 CVE-2021-32931 Access of Uninitialized Pointer vulnerability in Fatek Fvdesigner
An uninitialized pointer in FATEK Automation FvDesigner, Versions 1.5.88 and prior may be exploited while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
local
low complexity
fatek CWE-824
7.8
2021-08-11 CVE-2021-32939 Out-of-bounds Write vulnerability in Fatek Fvdesigner
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a project file that may permit arbitrary code execution.
local
low complexity
fatek CWE-787
7.8
2021-08-11 CVE-2021-32947 Stack-based Buffer Overflow vulnerability in Fatek Fvdesigner
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
local
low complexity
fatek CWE-121
7.8
2021-06-29 CVE-2021-32988 Out-of-bounds Write vulnerability in Fatek Winproladder 3.28/3.30
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
network
low complexity
fatek CWE-787
critical
9.8
2021-06-29 CVE-2021-32990 Out-of-bounds Read vulnerability in Fatek Winproladder 3.28/3.30
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.
network
low complexity
fatek CWE-125
critical
9.8
2021-06-29 CVE-2021-32992 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fatek Winproladder 3.28/3.30
FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code.
network
low complexity
fatek CWE-119
critical
9.8