Vulnerabilities > Hornerautomation > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-15 CVE-2023-7206 Out-of-bounds Write vulnerability in Hornerautomation Cscape
In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
local
low complexity
hornerautomation CWE-787
7.8
2023-06-06 CVE-2023-27916 Out-of-bounds Read vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT).
local
low complexity
hornerautomation CWE-125
7.8
2023-06-06 CVE-2023-28653 Use After Free vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP).
local
low complexity
hornerautomation CWE-416
7.8
2023-06-06 CVE-2023-29503 Stack-based Buffer Overflow vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP).
local
low complexity
hornerautomation CWE-121
7.8
2023-06-06 CVE-2023-31244 Access of Uninitialized Pointer vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected product does not properly validate user-supplied data.
local
low complexity
hornerautomation CWE-824
7.8
2023-06-06 CVE-2023-31278 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., HMI).
local
low complexity
hornerautomation CWE-119
7.8
2023-06-06 CVE-2023-32203 Out-of-bounds Write vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., HMI).
local
low complexity
hornerautomation CWE-787
7.8
2023-06-06 CVE-2023-32281 Out-of-bounds Read vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP).
local
low complexity
hornerautomation CWE-125
7.8
2023-06-06 CVE-2023-32289 Out-of-bounds Read vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP).
local
low complexity
hornerautomation CWE-125
7.8
2023-06-06 CVE-2023-32539 Out-of-bounds Write vulnerability in Hornerautomation Cscape and Cscape Envisionrv
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., HMI).
local
low complexity
hornerautomation CWE-787
7.8