<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability Research &amp; Exploit Development on TecSecurity Research</title><link>https://www.tecsecurity.io/</link><description>Recent content in Vulnerability Research &amp; Exploit Development on TecSecurity Research</description><generator>Hugo</generator><language>en-AU</language><lastBuildDate>Thu, 23 Jul 2026 12:00:00 +1000</lastBuildDate><atom:link href="https://www.tecsecurity.io/index.xml" rel="self" type="application/rss+xml"/><item><title>AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-450/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-450/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>ZDI-CAN-30702 - NVIDIA Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-30702/</link><pubDate>Wed, 22 Jul 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-30702/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full technical details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-438/</link><pubDate>Wed, 15 Jul 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-438/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DOE files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-316/</link><pubDate>Tue, 12 May 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-316/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of IPT files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-317/</link><pubDate>Tue, 12 May 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-317/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of IPT files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens SINEC NMS Improper Authentication Privilege Escalation Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-297/</link><pubDate>Thu, 23 Apr 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-297/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to escalate privileges on affected installations of Siemens SINEC NMS. Authentication is required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the web service listening on TCP port 443. The issue results from improper authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to escalate privileges to access protected resources.&lt;/p&gt;</description></item><item><title>NI LabVIEW LVCLASS File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-291/</link><pubDate>Wed, 15 Apr 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-291/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LVCLASS files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>NI LabVIEW LVLIB File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-290/</link><pubDate>Wed, 15 Apr 2026 12:00:00 +1000</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-290/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LVLIB files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Digilent DASYLab DSA File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-can-28444/</link><pubDate>Mon, 30 Mar 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28444/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent DASYLab. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DSA files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Digilent DASYLab DSA File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-can-28445/</link><pubDate>Mon, 30 Mar 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28445/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent DASYLab. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DSA files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Digilent DASYLab DSA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-can-28446/</link><pubDate>Mon, 30 Mar 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28446/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent DASYLab. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DSA files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-106/</link><pubDate>Wed, 18 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-106/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATPART files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD MODEL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2026-0875/</link><pubDate>Wed, 18 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2026-0875/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of MODEL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-084/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-084/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-085/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-085/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-086/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-086/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-087/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-087/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-088/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-088/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-089/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-089/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-090/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-090/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-091/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-091/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-092/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-092/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-093/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-093/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-094/</link><pubDate>Thu, 12 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-094/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Build. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SSD files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>ZDI-CAN-28757 - Ashlar-Vellum Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-28757/</link><pubDate>Fri, 06 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28757/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory Pro CTL File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-26-058/</link><pubDate>Tue, 03 Feb 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-26-058/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>ZDI-CAN-28675 - Ashlar-Vellum Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-28675/</link><pubDate>Thu, 22 Jan 2026 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28675/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1159/</link><pubDate>Fri, 19 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1159/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1160/</link><pubDate>Fri, 19 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1160/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1161/</link><pubDate>Fri, 19 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1161/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1162/</link><pubDate>Fri, 19 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1162/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1123/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1123/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATPART files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1129/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1129/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1131/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1131/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1134/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1134/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CTL files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1100/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1100/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1101/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1101/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1102/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1102/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1103/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1103/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap SLDPRT File Parsing Uninitialized Memory Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1124/</link><pubDate>Wed, 17 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1124/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SDLPRT files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>ZDI-CAN-28587 - Ashlar-Vellum Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-28587/</link><pubDate>Tue, 16 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28587/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>(0Day) Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1080/</link><pubDate>Thu, 11 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1080/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1081/</link><pubDate>Thu, 11 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1081/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1083/</link><pubDate>Thu, 11 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1083/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1084/</link><pubDate>Thu, 11 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1084/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1082/</link><pubDate>Thu, 11 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1082/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1062/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1062/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1065/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1065/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1068/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1068/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1063/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1063/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1064/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1064/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1066/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1066/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Fuji Electric Monitouch V-SFT V7 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1067/</link><pubDate>Wed, 10 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1067/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of V7 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap IGS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-1042/</link><pubDate>Tue, 09 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-1042/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of IGS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read before the start of an allocated array. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>ZDI-CAN-28447 - Ashlar-Vellum Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-28447/</link><pubDate>Thu, 04 Dec 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28447/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>ZDI-CAN-28172 - Ashlar-Vellum Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-28172/</link><pubDate>Tue, 11 Nov 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28172/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>ZDI-CAN-28173 - Ashlar-Vellum Vulnerability (Upcoming)</title><link>https://www.tecsecurity.io/advisories/zdi-can-28173/</link><pubDate>Tue, 11 Nov 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-can-28173/</guid><description>&lt;p&gt;This vulnerability is currently pending vendor remediation. Full details will be published following coordinated disclosure.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-955/</link><pubDate>Thu, 16 Oct 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-955/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-956/</link><pubDate>Thu, 16 Oct 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-956/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-954/</link><pubDate>Thu, 16 Oct 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-954/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap STP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-893/</link><pubDate>Fri, 12 Sep 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-893/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write before the start of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap NEU File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-874/</link><pubDate>Thu, 28 Aug 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-874/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of NEU files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap NEU File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-875/</link><pubDate>Thu, 28 Aug 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-875/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of NEU files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Simcenter Femap NEU File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-876/</link><pubDate>Thu, 28 Aug 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-876/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of NEU files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>ZDI Vanguard Award 2025: Most Prolific Researcher</title><link>https://www.tecsecurity.io/blog/zdi-vanguard-2025/</link><pubDate>Fri, 08 Aug 2025 10:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/blog/zdi-vanguard-2025/</guid><description>&lt;p align="center"&gt;&lt;img src="https://www.tecsecurity.io/images/zdi-vanguard-trophy-2025.jpg" alt="ZDI Vanguard Award — Most Prolific Researcher trophy" style="max-width:60%"&gt;&lt;/p&gt;
&lt;p&gt;At Black Hat USA 2025, Trend Micro&amp;rsquo;s Zero Day Initiative presented the &lt;strong&gt;ZDI Vanguard Award&lt;/strong&gt; to TecSecurity founder Rocco Calvi (&lt;a href="https://x.com/TecR0c"&gt;@TecR0c&lt;/a&gt;) for &lt;strong&gt;Most Prolific Researcher&lt;/strong&gt; &amp;ndash; recognising the researcher with the highest number of contracted vulnerability cases with ZDI. The award was presented at Trend Micro&amp;rsquo;s booth as part of ZDI&amp;rsquo;s 20th anniversary celebrations.&lt;/p&gt;
&lt;h2 id="by-the-numbers"&gt;By the Numbers&lt;/h2&gt;
&lt;p&gt;The award reflects over &lt;strong&gt;300 remote code execution vulnerabilities&lt;/strong&gt; reported to ZDI across a range of target categories:&lt;/p&gt;</description></item><item><title>NI LabVIEW VI File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-768/</link><pubDate>Fri, 01 Aug 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-768/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VI files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>NI LabVIEW VI File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-769/</link><pubDate>Fri, 01 Aug 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-769/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VI files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-714/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-714/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-716/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-716/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-713/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-713/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-721/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-721/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-720/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-720/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-715/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-715/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-717/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-717/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-724/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-724/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt LI File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-718/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-718/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LI files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt LI File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-726/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-726/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LI files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-719/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-719/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read before the start of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-723/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-723/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-725/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-725/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-722/</link><pubDate>Wed, 30 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-722/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD 3DM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-699/</link><pubDate>Tue, 29 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-699/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-640/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-640/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-642/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-642/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt AR File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-636/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-636/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of AR files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-630/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-630/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt LI File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-629/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-629/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LI files. The issue results from the lack of proper validation of user-supplied data, which can result in a read before the start of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-637/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-637/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-643/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-643/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-638/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-638/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-635/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-635/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-631/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-631/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-639/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-639/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-641/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-641/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-644/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-644/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-633/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-633/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-632/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-632/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-634/</link><pubDate>Tue, 22 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-634/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-511/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-511/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-512/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-512/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-513/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-513/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-522/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-522/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-527/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-527/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin CGM File Parsing Out-of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-495/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-495/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-487/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-487/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-488/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-488/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-489/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-489/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-491/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-491/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-492/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-492/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-493/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-493/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-497/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-497/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-498/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-498/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-500/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-500/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-501/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-501/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-504/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-504/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-506/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-506/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-518/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-518/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-524/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-524/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-525/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-525/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-528/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-528/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-529/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-529/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-531/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-531/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-536/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-536/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-544/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-544/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-545/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-545/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-547/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-547/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-548/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-548/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-549/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-549/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-550/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-550/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-551/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-551/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-552/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-552/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-553/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-553/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-554/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-554/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-555/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-555/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-556/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-556/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-557/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-557/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-558/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-558/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-560/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-560/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-561/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-561/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-562/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-562/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-563/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-563/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-564/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-564/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-565/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-565/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-568/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-568/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-570/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-570/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-573/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-573/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-494/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-494/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-486/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-486/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-490/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-490/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-509/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-509/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-510/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-510/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-559/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-559/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-566/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-566/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-569/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-569/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-507/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-507/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-496/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-496/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-502/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-502/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-503/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-503/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-514/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-514/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-520/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-520/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-521/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-521/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-523/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-523/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-526/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-526/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-530/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-530/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-532/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-532/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-533/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-533/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-534/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-534/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-535/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-535/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-537/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-537/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-538/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-538/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-540/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-540/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-541/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-541/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-543/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-543/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-546/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-546/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-567/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-567/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-572/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-572/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-499/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-499/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-515/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-515/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-516/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-516/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-517/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-517/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-519/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-519/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-539/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-539/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-542/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-542/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-571/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-571/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-485/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-485/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-505/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-505/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-508/</link><pubDate>Tue, 08 Jul 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-508/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-443/</link><pubDate>Wed, 25 Jun 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-443/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of GIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD 3DM File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-154/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-154/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of 3DM files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-161/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-161/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATPART files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATProduct File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-158/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-158/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATProduct files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATProduct File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-162/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-162/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATProduct files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATPRODUCT File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-159/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-159/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATPRODUCT files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD MODEL File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-157/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-157/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of MODEL files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD MODEL File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-160/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-160/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of MODEL files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD SLDPRT File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-156/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-156/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SLDPRT files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD SLDPRT File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-153/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-153/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SLDPRT files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-152/</link><pubDate>Tue, 18 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-152/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DOE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-129/</link><pubDate>Wed, 12 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-129/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-121/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-121/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-120/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-120/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CO files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-122/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-122/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of LI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-123/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-123/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-124/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-124/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-117/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-117/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-119/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-119/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-116/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-116/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-118/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-118/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-126/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-126/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VS files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt VS File Parsing Use of Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-115/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-115/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VS files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-125/</link><pubDate>Mon, 10 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-125/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-111/</link><pubDate>Thu, 06 Mar 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-111/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-086/</link><pubDate>Tue, 11 Feb 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-086/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor RTF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-070/</link><pubDate>Fri, 31 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-070/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-064/</link><pubDate>Fri, 31 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-064/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-071/</link><pubDate>Fri, 31 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-071/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-072/</link><pubDate>Fri, 31 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-072/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-058/</link><pubDate>Wed, 22 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-058/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files in the wrltojt module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-056/</link><pubDate>Wed, 22 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-056/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files in the wrltojt module. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-057/</link><pubDate>Wed, 22 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-057/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files in the wrltojt module. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-25-059/</link><pubDate>Wed, 22 Jan 2025 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-25-059/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files in the wrltojt module. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk Navisworks Freedom DWFX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1699/</link><pubDate>Thu, 19 Dec 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1699/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Navisworks Freedom. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWFX files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Rockwell Automation Arena Simulation DOE File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1714/</link><pubDate>Thu, 19 Dec 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1714/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DOE files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1649/</link><pubDate>Tue, 10 Dec 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1649/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DOE files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1654/</link><pubDate>Tue, 10 Dec 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1654/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DOE files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Rockwell Automation Arena Simulation DOE File Parsing Use of Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1650/</link><pubDate>Tue, 10 Dec 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1650/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DOE files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1567/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1567/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1572/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1572/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DJVU File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1579/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1579/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DJVU files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1544/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1544/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1568/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1568/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1545/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1545/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1541/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1541/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1546/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1546/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1548/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1548/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1549/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1549/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1550/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1550/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1552/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1552/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1553/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1553/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1554/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1554/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1560/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1560/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1561/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1561/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1562/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1562/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1565/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1565/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1569/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1569/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1570/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1570/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1573/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1573/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1578/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1578/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1588/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1588/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1590/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1590/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1592/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1592/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1593/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1593/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1551/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1551/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1563/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1563/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1564/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1564/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1566/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1566/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1574/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1574/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1575/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1575/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1576/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1576/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1577/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1577/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1540/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1540/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1543/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1543/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1547/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1547/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1558/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1558/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1559/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1559/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1542/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1542/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1571/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1571/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>IrfanView DXF File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1591/</link><pubDate>Thu, 21 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1591/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1525/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1525/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1521/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1521/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1522/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1522/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1523/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1523/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1524/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1524/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1527/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1527/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Siemens Tecnomatix Plant Simulation WRL File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1520/</link><pubDate>Tue, 19 Nov 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1520/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of WRL files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD 3DM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1435/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1435/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD ACTranslators 3DM File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1428/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1428/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of 3DM files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD ACTranslators CATPART File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1427/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1427/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATPART files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD ACTranslators STEP File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1430/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1430/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of STEP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD ACTranslators STP File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1429/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1429/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1434/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1434/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of CATPART files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1423/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1423/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD DWG File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1425/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1425/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1424/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1424/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD DXF File Parsing Unitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1426/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1426/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD MODEL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1438/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1438/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of MODEL files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD MODEL File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1432/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1432/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of MODEL files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Autodesk AutoCAD SLDPRT File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1437/</link><pubDate>Thu, 31 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1437/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of SLDPRT files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>Tungsten Automation Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1353/</link><pubDate>Fri, 11 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1353/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1352/</link><pubDate>Fri, 11 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1352/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Tungsten Automation Power PDF XPS File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1337/</link><pubDate>Fri, 11 Oct 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1337/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1251/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1251/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1252/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1252/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1255/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1255/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1246/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1246/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1247/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1247/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1258/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1258/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1262/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1262/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1266/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1266/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1263/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1263/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of JB2 files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1267/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1267/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1268/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1268/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1250/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1250/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PPM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor RTF File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1265/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1265/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of RTF files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1257/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1257/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1259/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1259/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1269/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1269/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1249/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1249/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1254/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1254/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1256/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1256/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor XPS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-24-1253/</link><pubDate>Tue, 17 Sep 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-24-1253/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Meta Oculus Security Vulnerability</title><link>https://www.tecsecurity.io/advisories/meta-oculus-2024/</link><pubDate>Mon, 18 Mar 2024 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/meta-oculus-2024/</guid><description>&lt;p&gt;Vulnerability identified and reported through Meta&amp;rsquo;s private bug bounty program (Bugcrowd). Resolved by vendor. No CVE was assigned.&lt;/p&gt;</description></item><item><title>Google Chromecast KeyChain Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2023-48417/</link><pubDate>Fri, 01 Dec 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2023-48417/</guid><description>&lt;p&gt;This vulnerability allows local attackers to disclose sensitive information on affected installations of Google Chromecast. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the KeyChain component. The issue is exploitable by any installed application with Intent-sending capabilities. An attacker can leverage this vulnerability to disclose stored credentials and sensitive information.&lt;/p&gt;
&lt;p&gt;Discovered and demonstrated at the HardPwn USA 2023 hardware hacking competition, held alongside the hardwear.io conference.&lt;/p&gt;</description></item><item><title>CVE-2023-36766 - Microsoft Excel Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2023-36766/</link><pubDate>Tue, 12 Sep 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2023-36766/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Excel files. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Memory Corruption Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-1370/</link><pubDate>Fri, 08 Sep 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-1370/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-1360/</link><pubDate>Fri, 08 Sep 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-1360/</guid><description>&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Inductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-1046/</link><pubDate>Tue, 08 Aug 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-1046/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the JavaSerializationCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.&lt;/p&gt;</description></item><item><title>(0Day) Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-1047/</link><pubDate>Tue, 08 Aug 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-1047/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the ParameterVersionJavaSerializationCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.&lt;/p&gt;</description></item><item><title>DoubleTrouble: Pre‑Auth RCE in Inductive Automation Ignition via Deserialization</title><link>https://www.tecsecurity.io/blog/doubletrouble-ignition-rce/</link><pubDate>Tue, 08 Aug 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/blog/doubletrouble-ignition-rce/</guid><description>&lt;p align="center"&gt;&lt;img src="https://www.tecsecurity.io/images/doubletrouble-ignition-rce.jpg" alt="DoubleTrouble — Inductive Automation Ignition Pre-Auth RCE" style="max-width:60%"&gt;&lt;/p&gt;
&lt;p&gt;This post details the exploitation of two critical deserialization vulnerabilities in Inductive Automation&amp;rsquo;s Ignition software — &lt;a href="https://www.cve.org/CVERecord?id=CVE-2023-39475"&gt;CVE-2023-39475&lt;/a&gt; and &lt;a href="https://www.cve.org/CVERecord?id=CVE-2023-39476"&gt;CVE-2023-39476&lt;/a&gt;. Both vulnerabilities carry a CVSS score of &lt;strong&gt;9.8&lt;/strong&gt; &lt;a href="https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;amp;version=3.0"&gt;(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)&lt;/a&gt; and enable unauthenticated remote code execution against affected installations.&lt;/p&gt;
&lt;p&gt;The proof-of-concept exploit, &lt;strong&gt;DoubleTrouble&lt;/strong&gt;, is &lt;a href="https://github.com/TecR0c/DoubleTrouble"&gt;available on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="background"&gt;Background&lt;/h2&gt;
&lt;p&gt;These vulnerabilities were discovered during preparation for &lt;strong&gt;Pwn2Own Miami 2023&lt;/strong&gt;. Unfortunately, the competition rules were &lt;a href="https://web.archive.org/web/20230101043715/https://www.zerodayinitiative.com/Pwn2OwnMiami2023Rules.html"&gt;changed on January 4th&lt;/a&gt;, rendering our submission invalid before the event took place.&lt;/p&gt;</description></item><item><title>Microsoft Office Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2023-35371/</link><pubDate>Tue, 08 Aug 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2023-35371/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Named Top Microsoft Office Researcher by MSRC (2023)</title><link>https://www.tecsecurity.io/blog/msrc-top-office-researcher-2023/</link><pubDate>Tue, 08 Aug 2023 10:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/blog/msrc-top-office-researcher-2023/</guid><description>&lt;p align="center"&gt;&lt;img src="https://www.tecsecurity.io/images/msrc-mvr-2023.jpg" alt="MSRC 2023 Most Valuable Researcher — Rocco Calvi" style="max-width:60%"&gt;&lt;/p&gt;
&lt;p&gt;The Microsoft Security Response Center (MSRC) &lt;a href="https://www.microsoft.com/en-us/msrc/blog/2023/08/congratulations-to-the-msrc-2023-most-valuable-security-researchers"&gt;announced the 2023 Most Valuable Security Researchers&lt;/a&gt;, recognising the top vulnerability researchers who reported high-impact security issues across Microsoft products during the July 2022 &amp;ndash; June 2023 reporting period.&lt;/p&gt;
&lt;p&gt;TecSecurity founder Rocco Calvi (&lt;a href="https://x.com/TecR0c"&gt;@TecR0c&lt;/a&gt;) was named one of the &lt;strong&gt;top three Microsoft Office researchers&lt;/strong&gt; for the year:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Congratulations to the top Office researchers this year: Mat Powell working with Trend Micro Zero Day Initiative, zcgonvh, &lt;strong&gt;Rocco Calvi (@TecR0c)&lt;/strong&gt;!&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-867/</link><pubDate>Thu, 15 Jun 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-867/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-868/</link><pubDate>Thu, 15 Jun 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-868/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>(0Day) Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-866/</link><pubDate>Thu, 15 Jun 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-866/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Pwning the TP-Link AX1800 WiFi 6 Router: Uncovered and Exploited a Memory Corruption Vulnerability</title><link>https://www.tecsecurity.io/blog/tp-link-ax1800/</link><pubDate>Tue, 23 May 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/blog/tp-link-ax1800/</guid><description>&lt;p align="center"&gt;&lt;img src="https://www.tecsecurity.io/images/tp-link-ax1800.jpg" alt="TP-Link Archer AX1800 (AX20) WiFi 6 Router" style="max-width:60%"&gt;&lt;/p&gt;
&lt;p&gt;In preparation for the Pwn2Own Toronto 2022 hacking contest organized by the Zero Day Initiative, Rocco Calvi (&lt;a href="https://twitter.com/TecR0c"&gt;@TecR0c&lt;/a&gt;) from TecSecurity dedicated his efforts to uncovering remote code execution vulnerabilities and crafting the corresponding exploits. Pwn2Own is a prestigious competition that rewards security researchers who demonstrate these skills against various targets. Discovered vulnerabilities are then shared with the appropriate vendors to enhance security.&lt;/p&gt;
&lt;p&gt;Regrettably, we could not participate in the Pwn2Own competition due to the requirement for a physical flash drive to be connected to the target device. Nonetheless, we made a valuable contribution to the event by coordinating the disclosure of a vulnerability we discovered in a router&amp;rsquo;s secure sharing feature with the vendor. This feature, based on the DLNA standard, enables users to share media such as music, photos, and videos across a home network using the MiniDLNA service (formerly known as ReadyMedia).&lt;/p&gt;</description></item><item><title>TP-Link AX1800 Dual-Band Wi-Fi 6 Router Remote Code Execution</title><link>https://www.tecsecurity.io/exploits/cve-2023-28760/</link><pubDate>Tue, 23 May 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2023-28760/</guid><description>&lt;p&gt;A memory corruption vulnerability in the TP-Link AX1800 WiFi 6 Router (Archer AX20) allows attackers to exploit a stack-based buffer overflow in the MiniDLNA service through a specially crafted database file. Attackers with access via Samba or FTP can upload a malicious &lt;code&gt;.TPDLNA/files.db&lt;/code&gt; database file to trigger remote code execution on the router.&lt;/p&gt;</description></item><item><title>CVE-2023-24953 - Microsoft Excel Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2023-24953/</link><pubDate>Tue, 09 May 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2023-24953/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of Excel files. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-496/</link><pubDate>Mon, 01 May 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-496/</guid><description>&lt;p&gt;This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the configuration of the lighttpd HTTP server. The issue results from allowing execution of files from untrusted sources. An attacker can leverage this vulnerability to execute code in the context of root.&lt;/p&gt;</description></item><item><title>NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-495/</link><pubDate>Mon, 01 May 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-495/</guid><description>&lt;p&gt;This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of JSON data. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor EMF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-355/</link><pubDate>Fri, 31 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-355/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of EMF files. Crafted data in a EMF can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor EMF File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-354/</link><pubDate>Fri, 31 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-354/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-351/</link><pubDate>Fri, 31 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-351/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-352/</link><pubDate>Fri, 31 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-352/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-353/</link><pubDate>Fri, 31 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-353/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-23-358/</link><pubDate>Fri, 31 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-23-358/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2023-23399 - Microsoft Excel Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2023-23399/</link><pubDate>Tue, 14 Mar 2023 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2023-23399/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of Excel files. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2022-41105 - Microsoft Excel Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-41105/</link><pubDate>Wed, 09 Nov 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-41105/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Excel files. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>Microsoft Word Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-41103/</link><pubDate>Wed, 09 Nov 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-41103/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Word documents. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-42342/</link><pubDate>Fri, 14 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-42342/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of fonts. Crafted data in a font can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>Microsoft Office Graphics Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-38049/</link><pubDate>Tue, 11 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-38049/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office graphics. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Microsoft Word Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-41031/</link><pubDate>Tue, 11 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-41031/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of Word documents. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1341/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1341/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1364/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1364/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1343/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1343/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1344/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1344/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor PDF File Parsing Use-After-Free Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1342/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1342/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of PDF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1386/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1386/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1385/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1385/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1388/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1388/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1389/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1389/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1390/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1390/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1393/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1393/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>PDF-XChange Editor TIF File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-22-1387/</link><pubDate>Fri, 07 Oct 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-22-1387/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2022-30159 - Microsoft Office Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-30159/</link><pubDate>Wed, 15 Jun 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-30159/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2022-30171 - Microsoft Office Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-30171/</link><pubDate>Wed, 15 Jun 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-30171/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2022-30172 - Microsoft Office Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-30172/</link><pubDate>Wed, 15 Jun 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-30172/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2022-29109 - Microsoft Excel Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2022-29109/</link><pubDate>Tue, 10 May 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2022-29109/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of Excel files. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Adobe Acrobat Reader DC Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2021-44715/</link><pubDate>Tue, 11 Jan 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2021-44715/</guid><description>&lt;p&gt;This vulnerability allows attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;</description></item><item><title>Adobe Acrobat Reader DC Security Feature Bypass Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2021-44713/</link><pubDate>Tue, 11 Jan 2022 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2021-44713/</guid><description>&lt;p&gt;This vulnerability allows attackers to bypass security features in affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;</description></item><item><title>CVE-2016-7232 - Microsoft Office Memory Corruption Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2016-7232/</link><pubDate>Thu, 10 Nov 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2016-7232/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2016-7233 - Microsoft Office Information Disclosure Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2016-7233/</link><pubDate>Thu, 10 Nov 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2016-7233/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. The issue results from the lack of proper validation of user-supplied data, which can result in an out-of-bounds read condition. An attacker can leverage this vulnerability to disclose information in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2016-7234 - Microsoft Office Memory Corruption Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2016-7234/</link><pubDate>Thu, 10 Nov 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2016-7234/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>CVE-2016-7235 - Microsoft Office Memory Corruption Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2016-7235/</link><pubDate>Thu, 10 Nov 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2016-7235/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of Office documents. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Foxit Reader FlateDecode Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-16-394/</link><pubDate>Wed, 29 Jun 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-16-394/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within FlateDecode. A specially crafted PDF with a FlateDecode stream can force a dangling pointer to be reused after it has been freed. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Foxit Reader Out-Of-Bounds Read/Write Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/foxit-2016-oob-rw/</link><pubDate>Wed, 29 Jun 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/foxit-2016-oob-rw/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code or disclose sensitive information on affected installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of PDF files, where the application could be exposed to an Out-of-Bounds Read or Out-of-Bounds Write vulnerability, which could lead to remote code execution or information disclosure.&lt;/p&gt;</description></item><item><title>Foxit Reader PDF Image Description Parsing Vulnerability</title><link>https://www.tecsecurity.io/advisories/foxit-2016-image-crash/</link><pubDate>Wed, 29 Jun 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/foxit-2016-image-crash/</guid><description>&lt;p&gt;This vulnerability could cause the application to crash unexpectedly when parsing a PDF file that contains malformed code in its image description. An attacker could potentially leverage this vulnerability for denial of service or further exploitation.&lt;/p&gt;</description></item><item><title>Foxit Reader XFA Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/foxit-2016-xfa-uaf/</link><pubDate>Wed, 29 Jun 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/foxit-2016-xfa-uaf/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must open a malicious XFA file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of XFA files whose layout direction is set as &amp;ldquo;lr-tb&amp;rdquo;. A Use-After-Free condition can be triggered when opening a specially crafted XFA file, which could be leveraged by attackers to execute remote code in the context of the current process.&lt;/p&gt;</description></item><item><title>Foxit Reader Use-After-Free Remote Code Execution Vulnerability</title><link>https://www.tecsecurity.io/advisories/zdi-16-027/</link><pubDate>Mon, 25 Jan 2016 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/zdi-16-027/</guid><description>&lt;p&gt;This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the handling of PDF files. The issue lies in assuming a buffer reference is still valid during a failure path. An attacker can leverage this vulnerability to execute code in the context of the current process.&lt;/p&gt;</description></item><item><title>Easy File Management Web Server Stack Buffer Overflow</title><link>https://www.tecsecurity.io/exploits/cve-2014-3791/</link><pubDate>Tue, 20 May 2014 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2014-3791/</guid><description>&lt;p&gt;A stack buffer overflow in Easy File Management Web Server versions 4.0 and 5.3 triggered through improper validation of the UserID cookie parameter, enabling remote arbitrary code execution.&lt;/p&gt;</description></item><item><title>freeFTPd PASS Command Buffer Overflow</title><link>https://www.tecsecurity.io/exploits/cve-2013-10042/</link><pubDate>Tue, 20 Aug 2013 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2013-10042/</guid><description>&lt;p&gt;freeFTPd 1.0.10 and below contains an overflow condition where user-supplied input is not properly validated when handling a specially crafted PASS command, enabling remote attackers to trigger a buffer overflow and achieve arbitrary code execution.&lt;/p&gt;</description></item><item><title>IBM Personal Communications iSeries Access WorkStation 5.9 Profile</title><link>https://www.tecsecurity.io/exploits/cve-2012-0201/</link><pubDate>Tue, 28 Feb 2012 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2012-0201/</guid><description>&lt;p&gt;A stack-based buffer overflow in IBM Personal Communications allows arbitrary code execution through malicious WorkStation profile files. The vulnerability exists in pcspref.dll where the application does not perform bounds checking on strcpy operations, enabling data to overwrite return addresses. The exploit bypasses DEP and ASLR on Windows XP, Vista, and Windows 7.&lt;/p&gt;</description></item><item><title>Microsoft SharePoint Server XSS in wizardlist.aspx Elevation of Privilege Vulnerability</title><link>https://www.tecsecurity.io/advisories/cve-2012-0145/</link><pubDate>Tue, 14 Feb 2012 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/advisories/cve-2012-0145/</guid><description>&lt;p&gt;A cross-site scripting vulnerability exists in Microsoft SharePoint 2010 that could result in information disclosure or elevation of privilege if a user clicks a specially crafted URL containing malicious JavaScript elements. Due to the vulnerability, when the malicious JavaScript is echoed back to the user&amp;rsquo;s browser, the resulting page could allow an attacker to issue SharePoint commands in the context of the authenticated user on the targeted SharePoint site.&lt;/p&gt;</description></item><item><title>Traq admincp/common.php Remote Code Execution</title><link>https://www.tecsecurity.io/exploits/cve-2011-10013/</link><pubDate>Mon, 12 Dec 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-10013/</guid><description>&lt;p&gt;This module exploits an arbitrary command execution vulnerability in Traq 2.0 to 2.3. The vulnerability exists in the &lt;code&gt;admincp/common.php&lt;/code&gt; script where the &lt;code&gt;header()&lt;/code&gt; function fails to halt execution flow, allowing malicious users to bypass authentication and leverage plugin functionality for arbitrary PHP code execution.&lt;/p&gt;</description></item><item><title>SCADA 3S CoDeSys CmpWebServer Stack Buffer Overflow</title><link>https://www.tecsecurity.io/exploits/cve-2011-5007/</link><pubDate>Fri, 02 Dec 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-5007/</guid><description>&lt;p&gt;A remote stack buffer overflow vulnerability in 3S-Smart Software Solutions CoDeSys SCADA Web Server Version 1.1.9.9, affecting versions 3.4 SP4 Patch 2 and earlier, allows remote code execution.&lt;/p&gt;</description></item><item><title>PmWiki pagelist.php Remote PHP Code Injection Exploit</title><link>https://www.tecsecurity.io/exploits/cve-2011-4453/</link><pubDate>Wed, 09 Nov 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-4453/</guid><description>&lt;p&gt;This module exploits an arbitrary command execution vulnerability in PmWiki versions 2.0.0 to 2.2.34. The vulnerable function is inside &lt;code&gt;/scripts/pagelist.php&lt;/code&gt;, allowing remote PHP code injection and execution.&lt;/p&gt;</description></item><item><title>phpLDAPadmin query_engine Remote PHP Code Injection</title><link>https://www.tecsecurity.io/exploits/cve-2011-4075/</link><pubDate>Mon, 24 Oct 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-4075/</guid><description>&lt;p&gt;This module exploits a vulnerability in &lt;code&gt;lib/functions.php&lt;/code&gt; in phpLDAPadmin versions 1.2.1.1 and earlier that allows attacker input to be parsed directly to the &lt;code&gt;create_function()&lt;/code&gt; PHP function, enabling remote code injection and execution.&lt;/p&gt;</description></item><item><title>ScriptFTP LIST Remote Buffer Overflow</title><link>https://www.tecsecurity.io/exploits/cve-2011-3976/</link><pubDate>Wed, 12 Oct 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-3976/</guid><description>&lt;p&gt;AmmSoft ScriptFTP client 3.3 and earlier is susceptible to a remote buffer overflow that is triggered when processing a sufficiently long filename during a FTP LIST command, resulting in overwriting the exception handler and enabling arbitrary code execution.&lt;/p&gt;</description></item><item><title>PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability</title><link>https://www.tecsecurity.io/exploits/cve-2011-4044/</link><pubDate>Wed, 05 Oct 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-4044/</guid><description>&lt;p&gt;This module exploits a function pointer control within SVUIGrd.ocx of PcVue 10.0. By setting a DWORD value for the &lt;code&gt;SaveObject()&lt;/code&gt; or &lt;code&gt;LoadObject()&lt;/code&gt; methods, an attacker can overwrite a function pointer and execute arbitrary code.&lt;/p&gt;</description></item><item><title>Plone and Zope XMLTools Remote Command Execution</title><link>https://www.tecsecurity.io/exploits/cve-2011-3587/</link><pubDate>Tue, 04 Oct 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-3587/</guid><description>&lt;p&gt;A vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the &lt;code&gt;p_&lt;/code&gt; class in &lt;code&gt;OFS/misc_.py&lt;/code&gt; and the use of Python modules.&lt;/p&gt;</description></item><item><title>Measuresoft ScadaPro Remote Command Execution</title><link>https://www.tecsecurity.io/exploits/cve-2011-3497/</link><pubDate>Fri, 16 Sep 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-3497/</guid><description>&lt;p&gt;Remote attackers can execute arbitrary commands on Measuresoft ScadaPro 4.0.0 and earlier through directory traversal exploitation of the &amp;lsquo;xf&amp;rsquo; (execute function) command. The vulnerability allows attackers to invoke &lt;code&gt;system()&lt;/code&gt; from msvcrt.dll to deploy backdoors and achieve remote code execution.&lt;/p&gt;</description></item><item><title>eSignal and eSignal Pro File Parsing Buffer Overflow in QUO</title><link>https://www.tecsecurity.io/exploits/cve-2011-3494/</link><pubDate>Tue, 06 Sep 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-3494/</guid><description>&lt;p&gt;eSignal and eSignal Pro versions 10.6.2425.1208 and earlier are unable to safely handle QUO, SUM and POR files. The vulnerability allows arbitrary code execution through a specially crafted file. Exploitation uses an egghunter technique and may take several seconds.&lt;/p&gt;</description></item><item><title>Mozilla Firefox Array.reduceRight() Integer Overflow</title><link>https://www.tecsecurity.io/exploits/cve-2011-2371/</link><pubDate>Tue, 21 Jun 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-2371/</guid><description>&lt;p&gt;This module exploits a vulnerability in Mozilla Firefox 3.6. When an array object is configured with a large length value, the &lt;code&gt;reduceRight()&lt;/code&gt; method may cause an invalid index being used, allowing arbitrary remote code execution.&lt;/p&gt;</description></item><item><title>VisiWave VWR File Parsing Vulnerability</title><link>https://www.tecsecurity.io/exploits/cve-2011-2386/</link><pubDate>Fri, 20 May 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-2386/</guid><description>&lt;p&gt;A vulnerability in VisiWave Site Survey Report where &lt;code&gt;VisiWaveReport.exe&lt;/code&gt; attempts to match a valid pointer based on the &amp;lsquo;Type&amp;rsquo; property but fails to properly validate when no match is found, returning the input as a pointer for later use in a CALL instruction. This enables arbitrary code execution and bypasses ASLR and DEP protections.&lt;/p&gt;</description></item><item><title>Real Networks Netzip Classic 7.5.1 86 File Parsing Buffer Overflow Vulnerability</title><link>https://www.tecsecurity.io/exploits/cve-2011-10016/</link><pubDate>Sun, 30 Jan 2011 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2011-10016/</guid><description>&lt;p&gt;A stack-based buffer overflow vulnerability in Real Networks Netzip Classic version 7.5.1 86 allows arbitrary code execution when a specially crafted zip file is opened by the victim.&lt;/p&gt;</description></item><item><title>Viscom Image Viewer CP Pro 8.0/Gold 6.0 ActiveX Control</title><link>https://www.tecsecurity.io/exploits/cve-2010-5193/</link><pubDate>Wed, 03 Mar 2010 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2010-5193/</guid><description>&lt;p&gt;A stack-based buffer overflow in the ImageViewer2.OCX ActiveX control exploited via an overly long argument to the &lt;code&gt;TifMergeMultiFiles()&lt;/code&gt; method, enabling code execution with user privileges. The module bypasses DEP and ASLR protections on Windows XP IE8, Vista, and Windows 7.&lt;/p&gt;</description></item><item><title>Viscom Software Movie Player Pro SDK ActiveX 6.8</title><link>https://www.tecsecurity.io/exploits/cve-2010-0356/</link><pubDate>Tue, 12 Jan 2010 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2010-0356/</guid><description>&lt;p&gt;A stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control within MoviePlayer.ocx version 6.8.0.0. The vulnerability allows remote attackers to execute arbitrary code via a long &lt;code&gt;strFontName&lt;/code&gt; parameter to the &lt;code&gt;DrawText&lt;/code&gt; method. The exploit bypasses DEP and ASLR protections.&lt;/p&gt;</description></item><item><title>TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability</title><link>https://www.tecsecurity.io/exploits/cve-2008-4779/</link><pubDate>Tue, 28 Oct 2008 12:00:00 +1100</pubDate><guid>https://www.tecsecurity.io/exploits/cve-2008-4779/</guid><description>&lt;p&gt;A stack-based buffer overflow vulnerability in TugZip 3.5 allows arbitrary code execution when a specially crafted zip file is opened. An attacker must convince the target to load the file by double click or file open.&lt;/p&gt;</description></item></channel></rss>