Alpha5 Smart Loader Firmware
by Fujielectric
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14794 | Cri | 0.64 | 9.8 | 0.02 | Oct 1, 2018 | Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the entire contents of the file to a heap-based buffer. | ||
| CVE-2022-24383 | Hig | 0.51 | 7.8 | 0.01 | Apr 12, 2022 | The affected product is vulnerable to an out-of-bounds read, which may result in code execution | ||
| CVE-2022-21228 | Hig | 0.51 | 7.8 | 0.01 | Apr 12, 2022 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. | ||
| CVE-2022-21214 | Hig | 0.51 | 7.8 | 0.01 | Apr 12, 2022 | The affected product is vulnerable to a heap-based buffer overflow, which may lead to code execution. | ||
| CVE-2019-13520 | Hig | 0.51 | 7.8 | 0.03 | Aug 20, 2019 | Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted project files to overflow the buffer and execute code under the privileges of the application. | ||
| CVE-2018-14788 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2018 | Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. A buffer overflow information disclosure vulnerability occurs when parsing certain file types. | ||
| CVE-2022-21202 | Low | 0.22 | 3.3 | 0.01 | Apr 12, 2022 | The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information. | ||
| CVE-2022-21168 | Low | 0.22 | 3.3 | 0.01 | Apr 12, 2022 | The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure. |
- risk 0.64cvss 9.8epss 0.02
Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the entire contents of the file to a heap-based buffer.
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to an out-of-bounds read, which may result in code execution
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
The affected product is vulnerable to a heap-based buffer overflow, which may lead to code execution.
- risk 0.51cvss 7.8epss 0.03
Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted project files to overflow the buffer and execute code under the privileges of the application.
- risk 0.35cvss 5.3epss 0.01
Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. A buffer overflow information disclosure vulnerability occurs when parsing certain file types.
- risk 0.22cvss 3.3epss 0.01
The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.
- risk 0.22cvss 3.3epss 0.01
The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure.