Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
Horner Automation Cscape 缓冲区错误漏洞
Vulnerability Description
Horner Automation Cscape是美国Horner Automation公司的一套用于工业控制系统开发的编程软件。 Horner Automation Cscape 9.90 SP 7及之前版本存在缓冲区错误漏洞,该漏洞源于未正确验证用户提供的数据,如果用户打开一个恶意形成的FNT文件,那么攻击者可以通过在内存缓冲区之外写入来执行当前进程内的任意代码。
CVSS Information
N/A
Vulnerability Type
N/A