Skip to main content

Vendor/product archive

omron / cx-supervisor CVEs

Beta · best-effort

20 CVEs tagged to omron / cx-supervisor0 Critical, 9 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2021-20836

Published Oct 19, 2021

Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19020

Published Feb 12, 2019

When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the application to read a value outside of an a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19018

Published Feb 12, 2019

An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a spe…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19015

Published Jan 28, 2019

An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An atta…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19019

Published Jan 22, 2019

A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit a…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19017

Published Jan 22, 2019

Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is refe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19013

Published Jan 22, 2019

An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-19011

Published Jan 22, 2019

CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the app…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17913

Published Nov 5, 2018

A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17909

Published Nov 5, 2018

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17907

Published Nov 5, 2018

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value ou…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-17905

Published Nov 5, 2018

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7525

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7523

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7521

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parses a specially crafted project file.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7519

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7517

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7515

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when pa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7513

Published Mar 21, 2018

In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1