CVE-2019-10951 | xxxCVE-2019-10951 – xxx
菜单

CVE-2019-10951

九月 30, 2020 - 未分类

  1. CVE-Search
  2. CVE-2019-10951
ID CVE-2019-10951
SummaryDelta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.
References
Vulnerable Configurations
  • cpe:2.3:a:deltaww:cncsoft_screeneditor:-:*:*:*:*:*:*:*
    cpe:2.3:a:deltaww:cncsoft_screeneditor:-:*:*:*:*:*:*:*
  • cpe:2.3:a:deltaww:cncsoft_screeneditor:1.00.88:*:*:*:*:*:*:*
    cpe:2.3:a:deltaww:cncsoft_screeneditor:1.00.88:*:*:*:*:*:*:*
CVSS
Base: 6.8 (as of 02-10-2020 – 14:43)
Impact:
Exploitability:
CWECWE-787
CAPEC

    Access
    VectorComplexityAuthentication
    NETWORKMEDIUMNONE
    Impact
    ConfidentialityIntegrityAvailability
    PARTIALPARTIALPARTIAL
    cvss-vector via4 AV:N/AC:M/Au:N/C:P/I:P/A:P
    refmap via4
    bid 107989
    misc
    Last major update02-10-2020 – 14:43
    Published17-04-2019 – 15:29
    Last modified02-10-2020 – 14:43

    Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51