Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cscape HIGH 7.8
CVE-2023-7206

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file…

Fix: 9.90+
Fix from $1,950 2024-01-15
Cscape HIGH 7.8
CVE-2023-32203

Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds wr…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-31244

The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arb…

No fix yet
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-31278

Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds re…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-27916

The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read.…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-28653

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vu…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-29503

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffe…

No fix yet
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-32289

The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds r…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-32539

Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds wr…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-32281

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds re…

Mitigation only
Fix from $1,950 2023-06-06
Cscape HIGH 7.8
CVE-2023-32545

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds re…

Mitigation only
Fix from $1,950 2023-06-06
Cscape Envision Rv HIGH 7.8
CVE-2023-0621

Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper …

Mitigation only
Fix from $1,950 2023-03-09
Cscape Envision Rv HIGH 7.8
CVE-2023-0622

Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper…

Mitigation only
Fix from $1,950 2023-03-09
Cscape Envision Rv HIGH 7.8
CVE-2023-0623

Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper…

Mitigation only
Fix from $1,950 2023-03-09
Rcc972 Firmware CRITICAL 9.8
CVE-2022-2641

Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthoriz…

Patch available
Fix from $2,300 2022-12-02
Rcc972 Firmware HIGH 7.5
CVE-2022-2642

Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out sensitive values and variable …

Patch available
Fix from $1,950 2022-12-02
Rcc972 Firmware HIGH 7.5
CVE-2022-2640

The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering.…

Patch available
Fix from $1,950 2022-12-02
Cscape HIGH 7.8
CVE-2022-3377

Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, …

Fix: 9.90+
Fix from $1,950 2022-11-15
Cscape HIGH 7.8
CVE-2022-3379

Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, t…

Fix: 9.90+
Fix from $1,950 2022-10-27
Cscape HIGH 7.8
CVE-2022-3378

Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, …

Fix: 9.90+
Fix from $1,950 2022-10-27
Cscape HIGH 7.8
CVE-2022-30540

The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code

Fix: 9.90+
Fix from $1,950 2022-06-02
Cscape HIGH 7.8
CVE-2022-29488

The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code.

Fix: 9.90+
Fix from $1,950 2022-06-02
Cscape HIGH 7.8
CVE-2022-28690

The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code.

Fix: 9.90+
Fix from $1,950 2022-06-02
Cscape HIGH 7.8
CVE-2022-27184

The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

Fix: 9.90+
Fix from $1,950 2022-06-02
Cscape Envisionrv HIGH 7.1
CVE-2021-44462

This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The is…

Fix: after 4.50.3.1
Fix from $1,950 2022-03-25
Cscape HIGH 7.8
CVE-2021-32975

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds…

Fix: 9.90+
Fix from $1,950 2021-08-25
Cscape HIGH 7.8
CVE-2021-32995

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds…

Fix: 9.90+
Fix from $1,950 2021-08-25
Cscape HIGH 7.8
CVE-2021-33015

Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds…

Fix: 9.90+
Fix from $1,950 2021-08-25
Cscape HIGH 7.8
CVE-2021-22678

Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruptio…

Fix: 9.90+
Fix from $1,950 2021-04-23
Cscape HIGH 7.8
CVE-2021-22682

Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write a…

Fix: 9.90+
Fix from $1,950 2021-04-23