Vulnerabilities > Hornerautomation > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-15 | CVE-2023-7206 | Out-of-bounds Write vulnerability in Hornerautomation Cscape In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape. | 7.8 |
2023-06-06 | CVE-2023-27916 | Out-of-bounds Read vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). | 7.8 |
2023-06-06 | CVE-2023-28653 | Use After Free vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). | 7.8 |
2023-06-06 | CVE-2023-29503 | Stack-based Buffer Overflow vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). | 7.8 |
2023-06-06 | CVE-2023-31244 | Access of Uninitialized Pointer vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected product does not properly validate user-supplied data. | 7.8 |
2023-06-06 | CVE-2023-31278 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g., HMI). | 7.8 |
2023-06-06 | CVE-2023-32203 | Out-of-bounds Write vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g., HMI). | 7.8 |
2023-06-06 | CVE-2023-32281 | Out-of-bounds Read vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). | 7.8 |
2023-06-06 | CVE-2023-32289 | Out-of-bounds Read vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). | 7.8 |
2023-06-06 | CVE-2023-32539 | Out-of-bounds Write vulnerability in Hornerautomation Cscape and Cscape Envisionrv The affected application lacks proper validation of user-supplied data when parsing project files (e.g., HMI). | 7.8 |