
CVE-2024-45467
https://notcve.org/view.php?id=CVE-2024-45467
08 Oct 2024 — A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), T... • https://cert-portal.siemens.com/productcert/html/ssa-583523.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2024-45466
https://notcve.org/view.php?id=CVE-2024-45466
08 Oct 2024 — A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V... • https://cert-portal.siemens.com/productcert/html/ssa-583523.html • CWE-125: Out-of-bounds Read •

CVE-2024-45465
https://notcve.org/view.php?id=CVE-2024-45465
08 Oct 2024 — A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V... • https://cert-portal.siemens.com/productcert/html/ssa-583523.html • CWE-125: Out-of-bounds Read •

CVE-2024-45464
https://notcve.org/view.php?id=CVE-2024-45464
08 Oct 2024 — A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V... • https://cert-portal.siemens.com/productcert/html/ssa-583523.html • CWE-125: Out-of-bounds Read •

CVE-2024-45463
https://notcve.org/view.php?id=CVE-2024-45463
08 Oct 2024 — A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V... • https://cert-portal.siemens.com/productcert/html/ssa-583523.html • CWE-125: Out-of-bounds Read •

CVE-2023-7066 – Siemens Teamcenter Visualization and JT2Go Out-of-bounds Read
https://notcve.org/view.php?id=CVE-2023-7066
12 Aug 2024 — The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. • https://cert-portal.siemens.com/productcert/html/ssa-722010.html • CWE-125: Out-of-bounds Read •

CVE-2024-37997
https://notcve.org/view.php?id=CVE-2024-37997
09 Jul 2024 — A vulnerability has been identified in JT Open (All versions < V11.5), PLM XML SDK (All versions < V7.1.0.014). The affected applications contain a stack based overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process. Se ha identificado una vulnerabilidad en JT Open (todas las versiones < V11.5), PLM XML SDK (todas las versiones < V7.1.0.014). Las aplicaciones afectadas contienen una vulnerabilidad de desbordam... • https://cert-portal.siemens.com/productcert/html/ssa-824889.html • CWE-121: Stack-based Buffer Overflow •

CVE-2024-37996
https://notcve.org/view.php?id=CVE-2024-37996
09 Jul 2024 — A vulnerability has been identified in JT Open (All versions < V11.5), PLM XML SDK (All versions < V7.1.0.014). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XML files. An attacker could leverage this vulnerability to crash the application causing denial of service condition. Se ha identificado una vulnerabilidad en JT Open (todas las versiones < V11.5), PLM XML SDK (todas las versiones < V7.1.0.014). Las aplicaciones afectadas contienen una... • https://cert-portal.siemens.com/productcert/html/ssa-824889.html • CWE-476: NULL Pointer Dereference •

CVE-2024-34086
https://notcve.org/view.php?id=CVE-2024-34086
14 May 2024 — A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), Teamcenter Visualization V14.3 (All versions < V14.3.0.7), Teamcenter Visualization V2312 (All versions < V2312.0001). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted CGM file. This could allow an attacker to execute code in the context of the current process. S... • https://cert-portal.siemens.com/productcert/html/ssa-661579.html • CWE-787: Out-of-bounds Write •

CVE-2024-34085
https://notcve.org/view.php?id=CVE-2024-34085
14 May 2024 — A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions < V14.1.0.13), Teamcenter Visualization V14.2 (All versions < V14.2.0.10), Teamcenter Visualization V14.3 (All versions < V14.3.0.7), Teamcenter Visualization V2312 (All versions < V2312.0001). The affected applications contain a stack overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process. Se ha i... • https://cert-portal.siemens.com/productcert/html/ssa-661579.html • CWE-121: Stack-based Buffer Overflow •