VYPR

Vendor CVEs

Deltaww

All CVEs

293 total · sorted by risk
  • CVE-2025-22880HigFeb 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the…

  • CVE-2024-12836HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this…

  • CVE-2024-12835HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this…

  • CVE-2024-12834HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this…

  • CVE-2024-47131HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.00

    If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.

  • CVE-2024-39605HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.03

    If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.

  • CVE-2024-39354HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.00

    If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.

  • CVE-2024-47966HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

  • CVE-2024-47965HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the…

  • CVE-2024-47964HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of…

  • CVE-2024-47963HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the…

  • CVE-2024-47962HigOct 10, 2024
    risk 0.51cvss 7.8epss 0.03

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the…

  • CVE-2024-7502HigAug 6, 2024
    risk 0.51cvss 7.8epss 0.00

    A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

  • CVE-2024-39880HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the…

  • CVE-2024-4192HigApr 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2024-1941HigMar 1, 2024
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

  • CVE-2024-1595HigFeb 29, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.

  • CVE-2023-5944HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legitimate user to execute a specially crafted file.

  • CVE-2023-5068HigSep 21, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.

  • CVE-2023-4685HigSep 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

  • CVE-2023-25177HigJun 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

  • CVE-2023-24014HigJun 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

  • CVE-2023-1145HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

  • CVE-2023-1135HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.00

    In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.

  • CVE-2023-0251HigFeb 8, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2023-0250HigFeb 8, 2023
    risk 0.51cvss 7.8epss 0.02

    Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2023-0249HigFeb 8, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2023-0124HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

  • CVE-2023-0123HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

  • CVE-2022-4634HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.05

    All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2022-1405HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.02

    CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buffer overflow condition.

  • CVE-2021-32969HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code.

  • CVE-2021-32965HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2022-1403HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.01

    ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition.

  • CVE-2022-1402HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.01

    ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

  • CVE-2022-1098HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

  • CVE-2022-26839HigMar 29, 2022
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

  • CVE-2021-43982HigDec 9, 2021
    risk 0.51cvss 7.8epss 0.10

    Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

  • CVE-2021-38422HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.

  • CVE-2021-38420HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

  • CVE-2021-38416HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

  • CVE-2021-38404HigSep 17, 2021
    risk 0.51cvss 7.8epss 0.01

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the…

  • CVE-2021-38402HigSep 17, 2021
    risk 0.51cvss 7.8epss 0.08

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could lead to a stack-based buffer overflow while trying to copy to a buffer during font string handling. An attacker could leverage…

  • CVE-2021-33019HigAug 30, 2021
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

  • CVE-2021-33007HigAug 30, 2021
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.

  • CVE-2021-27412HigJul 2, 2021
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

  • CVE-2021-22672HigMay 10, 2021
    risk 0.51cvss 7.8epss 0.10

    Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-27288HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

  • CVE-2020-27284HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.

  • CVE-2020-27280HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

Page 4 of 6