VYPR

Ispsoft

by Deltaww

CVEs (8)

  • CVE-2023-5131HigJan 18, 2024
    risk 0.53cvss 8.2epss 0.01

    A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

  • CVE-2025-4125HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

  • CVE-2025-4124HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

  • CVE-2025-22884HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

  • CVE-2025-22883HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

  • CVE-2025-22882HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.

  • CVE-2020-27280HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

  • CVE-2018-14800HigOct 3, 2018
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.