CVE-2023-25755

Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information may be disclosed and/or arbitrary code may be executed.
References
Link Resource
https://jvn.jp/en/vu/JVNVU99710864/ Third Party Advisory VDB Entry
https://www.electronics.jtekt.co.jp/en/topics/202303315311/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jtekt:screen_creator_advance_2:*:*:*:*:*:*:*:*
cpe:2.3:a:jtekt:screen_creator_advance_2:0.1.1.4:build01:*:*:*:*:*:*

History

18 Apr 2023, 17:13

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 09:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-25755

Mitre link : CVE-2023-25755

CVE.ORG link : CVE-2023-25755


JSON object : View

Products Affected

jtekt

  • screen_creator_advance_2
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer