CVE-2022-3377
15.11.2022, 21:15
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.Enginsight
Vendor | Product | Version |
---|---|---|
hornerautomation | cscape | 𝑥 < 9.90 |
hornerautomation | cscape | 9.90 |
hornerautomation | cscape | 9.90:sp1 |
hornerautomation | cscape | 9.90:sp2 |
hornerautomation | cscape | 9.90:sp3 |
hornerautomation | cscape | 9.90:sp4 |
hornerautomation | cscape | 9.90:sp5 |
hornerautomation | cscape | 9.90:sp6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration