Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3378


Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write.


Published

2022-10-27T23:15:10.127

Last Modified

2024-11-21T07:19:24.307

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-824
  • Type: Primary
    CWE-824

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hornerautomation cscape < 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes
Application hornerautomation cscape 9.90 Yes

References