Vulnerabilities > Fujielectric > V Server

DATE CVE VULNERABILITY TITLE RISK
2021-01-27 CVE-2021-22641 Out-of-bounds Write vulnerability in Fujielectric V-Server and V-Simulator
A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
local
low complexity
fujielectric CWE-787
7.8
2021-01-27 CVE-2021-22639 Access of Uninitialized Pointer vulnerability in Fujielectric V-Server and V-Simulator
An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
local
low complexity
fujielectric CWE-824
7.8
2021-01-27 CVE-2021-22637 Out-of-bounds Write vulnerability in Fujielectric V-Server and V-Simulator
Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
local
low complexity
fujielectric CWE-787
7.8
2020-04-13 CVE-2020-10646 Out-of-bounds Write vulnerability in Fujielectric V-Server 3.3.24.0/4.0.3.0
Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow.
local
low complexity
fujielectric CWE-787
7.8
2019-11-13 CVE-2019-18240 Out-of-bounds Write vulnerability in Fujielectric V-Server
In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.
network
low complexity
fujielectric CWE-787
critical
9.8
2019-06-12 CVE-2019-3947 Insufficiently Protected Credentials vulnerability in Fujielectric V-Server
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext.
network
low complexity
fujielectric CWE-522
critical
9.8
2019-06-12 CVE-2019-3946 Integer Overflow or Wraparound vulnerability in Fujielectric V-Server
Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005.
network
low complexity
fujielectric CWE-190
7.5
2018-09-13 CVE-2018-10637 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fujielectric V-Server 3.3.24.0/4.0.3.0
A maliciously crafted project file may cause a buffer overflow, which may allow the attacker to execute arbitrary code that affects Fuji Electric V-Server Lite 4.0.3.0 and prior.
local
low complexity
fujielectric CWE-119
7.8
2017-07-17 CVE-2017-9639 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fujielectric V-Server 3.3.22.0
An issue was discovered in Fuji Electric V-Server Version 3.3.22.0 and prior.
network
low complexity
fujielectric CWE-119
7.3