Vulnerabilities (CVE)

Filtered by vendor Deltaww Subscribe
Filtered by product Cncsoft Screeneditor
Total 12 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44768 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 4.3 MEDIUM 5.5 MEDIUM
Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.
CVE-2021-22672 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.
CVE-2021-22668 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 7.5 HIGH 9.8 CRITICAL
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.
CVE-2020-27281 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.
CVE-2020-16199 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
CVE-2020-16203 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.
CVE-2020-6976 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 4.3 MEDIUM 5.5 MEDIUM
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.
CVE-2020-16201 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 4.3 MEDIUM 3.3 LOW
Delta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information.
CVE-2020-7002 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file.
CVE-2019-10949 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 4.3 MEDIUM 5.5 MEDIUM
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files.
CVE-2019-10947 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. This may occur because CNCSoft lacks user input validation before copying data from project files onto the stack.
CVE-2019-10951 1 Deltaww 1 Cncsoft Screeneditor 2023-12-10 6.8 MEDIUM 7.8 HIGH
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.