VendorsHorner Automationcscape9.90
Vulnerabilities

Horner Automation Cscape 9.70 Service Pack 1 9.90

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2021-22678
Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruption. An attacker could leverage this vulnerability to execute code in the context of the current process.
Published 2021-04-23 · Modified
7.8EPSS 0.010
CVE-2021-32995
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute code in the context of the current process.
Published 2021-08-25 · Modified
7.8EPSS 0.010
CVE-2021-33015
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.
Published 2021-08-25 · Modified
7.8EPSS 0.010
CVE-2022-30540
Horner Automation Cscape Csfont
Published 2022-06-01 · Modified
7.8EPSS 0.010
CVE-2021-32975
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.
Published 2021-08-25 · Modified
7.8EPSS 0.010
CVE-2022-28690
Horner Automation Cscape Csfont
Published 2022-06-01 · Modified
7.8EPSS 0.009
CVE-2022-29488
Horner Automation Cscape Csfont
Published 2022-06-01 · Modified
7.8EPSS 0.009
CVE-2022-27184
Horner Automation Cscape Csfont
Published 2022-06-01 · Modified
7.8EPSS 0.009
CVE-2022-3377
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.
Published 2022-10-27 · Modified
7.8EPSS 0.002
CVE-2022-3378
Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write.
Published 2022-10-27 · Modified
7.8EPSS 0.002
CVE-2022-3379
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.
Published 2022-10-27 · Modified
7.8EPSS 0.002
CVE-2023-28653
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-29503
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-27916
The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-31244
The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-31278
Horner Automation Cscape Out-of-bounds Read
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-32203
Horner Automation Cscape Out-of-bounds Write
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-32281
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-32289
The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-32539
Horner Automation Cscape Out-of-bounds Write
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2023-32545
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Published 2023-06-06 · Modified
7.8EPSS 0.002
CVE-2021-22682
Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write access. This may allow unprivileged users to modify the binaries and configuration files and lead to local privilege escalation.
Published 2021-04-23 · Modified
7.8EPSS 0.002
CVE-2023-7206
Horner Automation Cscape Stack-Based Buffer Overflow
Published 2024-01-15 · Modified
7.8EPSS 0.002