Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3377


Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.


Published

2022-11-15T21:15:37.950

Last Modified

2024-11-21T07:19:24.177

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-824

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hornerautomation cscape < 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes

References