CVE-2024-12212 – Horner Automation Cscape Out-of-bounds Read
https://notcve.org/view.php?id=CVE-2024-12212
13 Dec 2024 — The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code. • https://hornerautomation.com/cscape-software-free/cscape-software • CWE-125: Out-of-bounds Read •
CVE-2024-9508 – Horner Automation Cscape Out-of-bounds Read
https://notcve.org/view.php?id=CVE-2024-9508
13 Dec 2024 — Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code. • https://hornerautomation.com/cscape-software-free/cscape-software • CWE-125: Out-of-bounds Read •
CVE-2023-7206 – Horner Automation Cscape Stack-Based Buffer Overflow
https://notcve.org/view.php?id=CVE-2023-7206
15 Jan 2024 — In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape. En las versiones 9.90 SP10 y anteriores de Horner Automation Cscape, los atacantes locales pueden aprovechar esta vulnerabilidad si un usuario abre un archivo CSP malicioso, lo que resultaría en la ejecución de código arbitrario en las instalaciones afectadas de Cscape. • https://hornerautomation.com/cscape-software • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2022-3377
https://notcve.org/view.php?id=CVE-2022-3377
27 Oct 2022 — Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read. Cscape versión 9.90 SP 6 y anteriores de Horner Automation no valida correctamente los datos proporcionados por el usuario. Si un usuario abre un archivo FNT formado con fines malintencionados, un atacante podr... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-277-03 • CWE-824: Access of Uninitialized Pointer •
CVE-2022-3378
https://notcve.org/view.php?id=CVE-2022-3378
27 Oct 2022 — Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write. Horner Automation´s Cscape versión 9.90 SP 7 y anteriores no valida correctamente los datos proporcionados por el usuario. Si un usuario abre un archivo FNT formado con fines malintencionados, un atacante podr... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-277-03 • CWE-824: Access of Uninitialized Pointer •
CVE-2022-3379
https://notcve.org/view.php?id=CVE-2022-3379
27 Oct 2022 — Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer. Horner Automation´s Cscape versión 9.90 SP 7 y anteriores no validan correctamente los datos proporcionados por el usuario. Si un usuario abre un archivo FNT formado con fines malintencionados, un atacante podría ejecutar código arbitrario dentro del pr... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-277-03 • CWE-787: Out-of-bounds Write •
CVE-2022-30540 – Horner Automation Cscape Csfont
https://notcve.org/view.php?id=CVE-2022-30540
01 Jun 2022 — The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code El producto afectado es vulnerable a un desbordamiento de búfer en la región heap de la memoria por medio de un puntero no inicializado, lo que puede permitir a un atacante ejecutar código arbitrario • https://www.cisa.gov/uscert/ics/advisories/icsa-22-146-02 • CWE-122: Heap-based Buffer Overflow CWE-824: Access of Uninitialized Pointer •
CVE-2022-29488 – Horner Automation Cscape Csfont
https://notcve.org/view.php?id=CVE-2022-29488
01 Jun 2022 — The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code. El producto afectado es vulnerable a una lectura fuera de límites por medio de un puntero no inicializado, lo que puede permitir a un atacante ejecutar código arbitrario • https://www.cisa.gov/uscert/ics/advisories/icsa-22-146-02 • CWE-125: Out-of-bounds Read CWE-824: Access of Uninitialized Pointer •
CVE-2022-28690 – Horner Automation Cscape Csfont
https://notcve.org/view.php?id=CVE-2022-28690
01 Jun 2022 — The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code. El producto afectado es vulnerable a una escritura fuera de límites por medio de un puntero no inicializado, lo que puede permitir a un atacante ejecutar código arbitrario • https://www.cisa.gov/uscert/ics/advisories/icsa-22-146-02 • CWE-787: Out-of-bounds Write CWE-824: Access of Uninitialized Pointer •
CVE-2022-27184 – Horner Automation Cscape Csfont
https://notcve.org/view.php?id=CVE-2022-27184
01 Jun 2022 — The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code. El producto afectado es vulnerable a una escritura fuera de límites, que puede permitir a un atacante ejecutar código arbitrario • https://www.cisa.gov/uscert/ics/advisories/icsa-22-146-02 • CWE-787: Out-of-bounds Write •