High severity7.8NVD Advisory· Published Dec 4, 2018· Updated Jun 17, 2026
CVE-2018-18989
CVE-2018-18989
Description
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/106106nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-18-338-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.