VYPR

Labview

by Ni

CVEs (50)

  • CVE-2025-2630HigApr 9, 2025
    risk 0.47cvss 7.3epss 0.00

    There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This…

  • CVE-2025-2629HigApr 9, 2025
    risk 0.47cvss 7.3epss 0.00

    There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the…

  • CVE-2026-18445MedAug 25, 2026
    risk 0.43cvss 6.6epss 0.00

    There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI…

  • CVE-2026-18444MedAug 25, 2026
    risk 0.43cvss 6.6epss 0.00

    There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open…

  • CVE-2022-27237MedApr 21, 2022
    risk 0.40cvss 6.1epss 0.01

    There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install…

  • CVE-2024-6638MedJul 22, 2024
    risk 0.36cvss 5.5epss 0.00

    An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This vulnerability affects LabVIEW 2024 Q1…

  • CVE-2002-0748Aug 12, 2002
    risk 0.04cvss —epss 0.10

    LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/newline combinations.

  • CVE-2013-5023Aug 6, 2013
    risk 0.00cvss —epss 0.01

    The ActiveX controls in the HelpAsst component in NI Help Links in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and other products allow remote attackers to cause a denial of service by triggering the display of local .chm files.

  • CVE-2013-5022Aug 6, 2013
    risk 0.00cvss —epss 0.03

    Absolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and other products allows remote attackers to create and execute arbitrary files via a full pathname…

  • CVE-2013-5021Aug 6, 2013
    risk 0.00cvss —epss 0.02

    Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other…

Page 3 of 3