Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hornerautomation vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-32545
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the curre...
Hornerautomation Cscape 9.90
Hornerautomation Cscape Envisionrv 4.70
NA
CVE-2023-31244
The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
Hornerautomation Cscape 9.90
Hornerautomation Cscape Envisionrv 4.70
NA
CVE-2023-32281
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current proce...
Hornerautomation Cscape 9.90
Hornerautomation Cscape Envisionrv 4.70
NA
CVE-2023-32289
The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Hornerautomation Cscape 9.90
Hornerautomation Cscape Envisionrv 4.70
NA
CVE-2023-28653
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Hornerautomation Cscape 9.90
Hornerautomation Cscape Envisionrv 4.70
6.8
CVSSv2
CVE-2019-13545
In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.
Hornerautomation Cscape
6.8
CVSSv2
CVE-2019-13541
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an malicious user to access information and remotely execute arbitrary code.
Hornerautomation Cscape
5.8
CVSSv2
CVE-2021-44462
This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocate...
Hornerautomation Cscape Envisionrv
NA
CVE-2022-2641
Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an malicious user to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.
Hornerautomation Rcc972 Firmware 15.40
NA
CVE-2022-2642
Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an malicious user to read out sensitive values and variable keys from the device.
Hornerautomation Rcc972 Firmware 15.40
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
race condition
CVE-2024-4249
CVE-2024-4244
CVE-2023-20198
TCP
CVE-2022-48648
CVE-2022-48636
CVE-2024-21345
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »