VendorsFuji Electricv-serverall versions
Vulnerabilities

Fuji Electric V-Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2019-18240
In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.
Published 2019-11-13 · Modified
9.8EPSS 0.143
CVE-2018-14823
Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.040
CVE-2018-14813
Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.039
CVE-2018-14811
Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.036
CVE-2018-14815
Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.036
CVE-2018-14817
Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.036
CVE-2018-14819
Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.036
CVE-2018-14809
Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote code execution.
Published 2018-09-26 · Modified
9.8EPSS 0.027
CVE-2019-3947
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.
Published 2019-06-12 · Modified
9.8EPSS 0.016
CVE-2021-22637
Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
Published 2021-01-27 · Modified
7.8EPSS 0.021
CVE-2021-22641
A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
Published 2021-01-27 · Modified
7.8EPSS 0.021
CVE-2021-22639
An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
Published 2021-01-27 · Modified
7.8EPSS 0.019
CVE-2018-10637
A maliciously crafted project file may cause a buffer overflow, which may allow the attacker to execute arbitrary code that affects Fuji Electric V-Server Lite 4.0.3.0 and prior.
Published 2018-09-13 · Modified
7.8EPSS 0.018
CVE-2021-22655
Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
Published 2021-01-27 · Modified
7.8EPSS 0.012
CVE-2021-22653
Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).
Published 2021-01-27 · Modified
7.8EPSS 0.012
CVE-2020-25171
Fuji Electric V-Server Lite
Published 2021-02-19 · Modified
7.8EPSS 0.012
CVE-2021-38413
Fuji Electric Tellus Lite V-Simulator stack based buffer overflow
Published 2021-12-20 · Modified
7.8EPSS 0.010
CVE-2021-38415
Fuji Electric Tellus Lite V-Simulator heap based buffer overflow
Published 2021-12-20 · Modified
7.8EPSS 0.010
CVE-2022-30549
Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
Published 2022-06-16 · Modified
7.8EPSS 0.009
CVE-2022-29524
Out-of-bounds write vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
Published 2022-06-14 · Modified
7.8EPSS 0.009
CVE-2022-29506
Out-of-bounds read vulnerability exist in the simulator module contained in the graphic editor 'V-SFT' v6.1.3.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
Published 2022-06-14 · Modified
7.8EPSS 0.009
CVE-2021-38401
Fuji Electric Tellus Lite V-Simulator untrusted pointer dereference
Published 2021-12-20 · Modified
7.8EPSS 0.009
CVE-2021-38419
Fuji Electric Tellus Lite V-Simulator out of bounds write
Published 2021-12-20 · Modified
7.8EPSS 0.009
CVE-2020-10646
Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to read data, when parsing VPR files, is too small.
Published 2020-04-13 · Modified
7.8EPSS 0.008
CVE-2022-29522
Use after free vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
Published 2022-06-14 · Modified
7.8EPSS 0.008
CVE-2021-38421
Fuji Electric Tellus Lite V-Simulator out of bounds read
Published 2021-12-20 · Modified
7.8EPSS 0.008
CVE-2021-38409
Fuji Electric Tellus Lite V-Simulator uninitialized pointer
Published 2021-12-20 · Modified
7.8EPSS 0.007
CVE-2023-47586
Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
Published 2023-11-15 · Modified
7.8EPSS 0.003
CVE-2023-31239
Stack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attacker to execute arbitrary code by having user open a specially crafted VPR file.
Published 2023-06-19 · Modified
7.8EPSS 0.003
CVE-2023-47584
Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
Published 2023-11-15 · Modified
7.8EPSS 0.003
CVE-2023-47585
Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.
Published 2023-11-15 · Modified
7.8EPSS 0.003
CVE-2022-47908
Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
Published 2023-01-03 · Modified
7.8EPSS 0.003
CVE-2022-41645
Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
Published 2023-01-03 · Modified
7.8EPSS 0.002
CVE-2022-47317
Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.
Published 2023-01-03 · Modified
7.8EPSS 0.002
CVE-2019-3946
Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. An unauthenticated, remote attacker can crash vserver.exe due to an integer overflow in the UDP message handling logic.
Published 2019-06-12 · Modified
7.5EPSS 0.023
CVE-2017-9639
An issue was discovered in Fuji Electric V-Server Version 3.3.22.0 and prior. A memory corruption vulnerability has been identified (aka improper restriction of operations within the bounds of a memory buffer), which may allow remote code execution.
Published 2017-07-17 · Modified
7.5EPSS 0.020