Vulnerabilities > Omron > High

DATE CVE VULNERABILITY TITLE RISK
2019-06-12 CVE-2019-10971 Untrusted Search Path vulnerability in Omron Network Configurator for Devicenet Safety 3.41
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.
local
low complexity
omron CWE-426
7.8
2019-02-12 CVE-2018-19018 Access of Uninitialized Pointer vulnerability in Omron Cx-Supervisor
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files.
local
low complexity
omron CWE-824
7.3
2019-01-30 CVE-2018-19027 Incorrect Type Conversion or Cast vulnerability in Omron Cx-One and Cx-Protocol
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files.
local
low complexity
omron CWE-704
7.8
2019-01-28 CVE-2018-19015 OS Command Injection vulnerability in Omron Cx-Supervisor
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.
local
low complexity
omron CWE-78
7.3
2019-01-22 CVE-2018-19019 Incorrect Type Conversion or Cast vulnerability in Omron Cx-Supervisor
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior).
local
low complexity
omron CWE-704
7.3
2019-01-22 CVE-2018-19017 Use After Free vulnerability in Omron Cx-Supervisor
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior).
network
low complexity
omron CWE-416
8.8
2019-01-22 CVE-2018-19011 Code Injection vulnerability in Omron Cx-Supervisor
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file.
network
low complexity
omron CWE-94
8.8
2018-12-04 CVE-2018-18993 Out-of-bounds Write vulnerability in Omron Cx-One, Cx-Programmer and Cx-Server
Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior).
local
low complexity
omron CWE-787
7.8
2018-12-04 CVE-2018-18989 Use After Free vulnerability in Omron Cx-One, Cx-Programmer and Cx-Server
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory.
local
low complexity
omron CWE-416
7.8
2018-11-05 CVE-2018-17913 Incorrect Type Conversion or Cast vulnerability in Omron Cx-Supervisor
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.
local
low complexity
omron CWE-704
7.8