fujielectric CVE Vulnerabilities & Metrics

Focus on fujielectric vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fujielectric Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fujielectric. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fujielectric CVEs: 102
Earliest CVE date: 17 Jul 2017, 19:29 UTC
Latest CVE date: 28 Nov 2024, 00:15 UTC

Latest CVE reference: CVE-2024-11933

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 20

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -4.76%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -4.76%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fujielectric CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.3

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 52
4.0-6.9 37
7.0-8.9 12
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS fujielectric CVEs

These are the five CVEs with the highest CVSS scores for fujielectric, sorted by severity first and recency.

All CVEs for fujielectric

CVE-2024-11933 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT X1 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X1 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24548.

CVE-2024-11803 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24771.

CVE-2024-11802 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24770.

CVE-2024-11801 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24769.

CVE-2024-11800 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24768.

CVE-2024-11799 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24664.

CVE-2024-11798 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT X1 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X1 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24663.

CVE-2024-11797 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24662.

CVE-2024-11796 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V9C files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24506.

CVE-2024-11795 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24505.

CVE-2024-11794 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V10 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24504.

CVE-2024-11793 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V9C files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24503.

CVE-2024-11792 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24502.

CVE-2024-11791 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V8C File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8C files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24450.

CVE-2024-11790 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24449.

CVE-2024-11789 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24448.

CVE-2024-11787 fujielectric vulnerability CVSS: 0 28 Nov 2024, 00:15 UTC

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V10 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24413.

CVE-2024-37029 fujielectric vulnerability CVSS: 0 13 Jun 2024, 18:15 UTC

Fuji Electric Tellus Lite V-Simulator is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVE-2024-37022 fujielectric vulnerability CVSS: 0 13 Jun 2024, 18:15 UTC

Fuji Electric Tellus Lite V-Simulator is vulnerable to an out-of-bounds write, which could allow an attacker to manipulate memory, resulting in execution of arbitrary code.

CVE-2024-5597 fujielectric vulnerability CVSS: 0 10 Jun 2024, 17:16 UTC

Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution.

CVE-2023-5299 fujielectric vulnerability CVSS: 0 22 Nov 2023, 01:15 UTC

A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.

CVE-2023-40152 fujielectric vulnerability CVSS: 0 22 Nov 2023, 01:15 UTC

When Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file an out of bounds write may occur.

CVE-2023-35127 fujielectric vulnerability CVSS: 0 22 Nov 2023, 01:15 UTC

Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.

CVE-2023-47586 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Multiple heap-based buffer overflow vulnerabilities exist in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

CVE-2023-47585 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Out-of-bounds read vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

CVE-2023-47584 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Out-of-bounds write vulnerability exists in V-Server V4.0.18.0 and earlier and V-Server Lite V4.0.18.0 and earlier. If a user opens a specially crafted VPR file, information may be disclosed and/or arbitrary code may be executed.

CVE-2023-47583 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Multiple out-of-bounds read vulnerabilities exist in TELLUS Simulator V4.0.17.0 and earlier. If a user opens a specially crafted file (X1 or V9 file), information may be disclosed and/or arbitrary code may be executed.

CVE-2023-47582 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Access of uninitialized pointer vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

CVE-2023-47581 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Out-of-bounds read vulnerability exists in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

CVE-2023-47580 fujielectric vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Multiple improper restriction of operations within the bounds of a memory buffer issues exist in TELLUS V4.0.17.0 and earlier and TELLUS Lite V4.0.17.0 and earlier. If a user opens a specially crafted file (X1, V8, or V9 file), information may be disclosed and/or arbitrary code may be executed.

CVE-2023-32542 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Out-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-32538 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Stack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may lead to information disclosure and/or arbitrary code execution. This vulnerability is different from CVE-2023-32273 and CVE-2023-32201.

CVE-2023-32288 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Out-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-32276 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Stack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-32273 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Stack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may lead to information disclosure and/or arbitrary code execution. This vulnerability is different from CVE-2023-32538 and CVE-2023-32201.

CVE-2023-32270 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Access of memory location after end of buffer issue exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 file may lead to information disclosure and/or arbitrary code execution.

CVE-2023-32201 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Stack-based buffer overflow vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM2 file may lead to information disclosure and/or arbitrary code execution. This vulnerability is different from CVE-2023-32538 and CVE-2023-32273.

CVE-2023-31239 fujielectric vulnerability CVSS: 0 19 Jun 2023, 05:15 UTC

Stack-based buffer overflow vulnerability in V-Server v4.0.15.0 and V-Server Lite v4.0.15.0 and earlier allows an attacker to execute arbitrary code by having user open a specially crafted VPR file.

CVE-2023-29498 fujielectric vulnerability CVSS: 0 13 Jun 2023, 10:15 UTC

Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a specially crafted project file, sensitive information on the system where the affected product is installed may be disclosed.

CVE-2023-29167 fujielectric vulnerability CVSS: 0 13 Jun 2023, 10:15 UTC

Out-of-bound reads vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed.

CVE-2023-29160 fujielectric vulnerability CVSS: 0 13 Jun 2023, 10:15 UTC

Stack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information on the system where the affected product is installed may be disclosed or arbitrary code may be executed.

CVE-2022-3085 fujielectric vulnerability CVSS: 0 19 Jan 2023, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which may allow an attacker to execute arbitrary code.

CVE-2022-3087 fujielectric vulnerability CVSS: 0 17 Jan 2023, 00:15 UTC

Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code.

CVE-2022-47908 fujielectric vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.

CVE-2022-47317 fujielectric vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.

CVE-2022-46360 fujielectric vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-43448 fujielectric vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

Out-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-41645 fujielectric vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrary code by having a user to open a specially crafted project file.

CVE-2022-1738 fujielectric vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to leak sensitive data from the process memory.

CVE-2022-1523 fujielectric vulnerability CVSS: 0 19 Oct 2022, 18:15 UTC

Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an attacker to overwrite program memory to manipulate the flow of information.

CVE-2022-1888 fujielectric vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted project file, which may allow an attacker to execute arbitrary code.

CVE-2022-30549 fujielectric vulnerability CVSS: 6.8 16 Jun 2022, 02:15 UTC

Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-30546 fujielectric vulnerability CVSS: 6.8 16 Jun 2022, 02:15 UTC

Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-30538 fujielectric vulnerability CVSS: 6.8 16 Jun 2022, 02:15 UTC

Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-29925 fujielectric vulnerability CVSS: 6.8 14 Jun 2022, 09:15 UTC

Access of uninitialized pointer vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-29524 fujielectric vulnerability CVSS: 6.8 14 Jun 2022, 09:15 UTC

Out-of-bounds write vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-29522 fujielectric vulnerability CVSS: 6.8 14 Jun 2022, 09:15 UTC

Use after free vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-29506 fujielectric vulnerability CVSS: 6.8 14 Jun 2022, 09:15 UTC

Out-of-bounds read vulnerability exist in the simulator module contained in the graphic editor 'V-SFT' v6.1.3.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-26302 fujielectric vulnerability CVSS: 6.8 14 Jun 2022, 09:15 UTC

Heap-based buffer overflow exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

CVE-2022-24383 fujielectric vulnerability CVSS: 6.8 12 Apr 2022, 17:15 UTC

The affected product is vulnerable to an out-of-bounds read, which may result in code execution

CVE-2022-21228 fujielectric vulnerability CVSS: 6.8 12 Apr 2022, 17:15 UTC

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

CVE-2022-21214 fujielectric vulnerability CVSS: 6.8 12 Apr 2022, 17:15 UTC

The affected product is vulnerable to a heap-based buffer overflow, which may lead to code execution.

CVE-2022-21202 fujielectric vulnerability CVSS: 4.3 12 Apr 2022, 17:15 UTC

The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.

CVE-2022-21168 fujielectric vulnerability CVSS: 4.3 12 Apr 2022, 17:15 UTC

The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure.

CVE-2021-38421 fujielectric vulnerability CVSS: 5.8 20 Dec 2021, 21:15 UTC

Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds read, which may allow an attacker to read sensitive information from other memory locations or cause a crash.

CVE-2021-38419 fujielectric vulnerability CVSS: 6.8 20 Dec 2021, 21:15 UTC

Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds write, which can result in data corruption, a system crash, or code execution.

CVE-2021-38415 fujielectric vulnerability CVSS: 6.8 20 Dec 2021, 21:15 UTC

Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable a heap-based buffer overflow when parsing a specially crafted project file, which may allow an attacker to execute arbitrary code.

CVE-2021-38413 fujielectric vulnerability CVSS: 6.8 20 Dec 2021, 21:15 UTC

Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to a stack-based buffer overflow, which may allow an attacker to achieve code execution.

CVE-2021-38409 fujielectric vulnerability CVSS: 6.8 20 Dec 2021, 21:15 UTC

Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an access of uninitialized pointer, which may allow an attacker read from or write to unexpected memory locations, leading to a denial-of-service.

CVE-2021-38401 fujielectric vulnerability CVSS: 6.8 20 Dec 2021, 21:15 UTC

Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an untrusted pointer dereference, which may allow an attacker to execute arbitrary code and cause the application to crash.

CVE-2020-25171 fujielectric vulnerability CVSS: 6.8 19 Feb 2021, 18:15 UTC

The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-22655 fujielectric vulnerability CVSS: 6.8 27 Jan 2021, 20:15 UTC

Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

CVE-2021-22653 fujielectric vulnerability CVSS: 6.8 27 Jan 2021, 20:15 UTC

Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

CVE-2021-22641 fujielectric vulnerability CVSS: 6.8 27 Jan 2021, 20:15 UTC

A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

CVE-2021-22639 fujielectric vulnerability CVSS: 6.8 27 Jan 2021, 20:15 UTC

An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

CVE-2021-22637 fujielectric vulnerability CVSS: 6.8 27 Jan 2021, 20:15 UTC

Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution on the Tellus Lite V-Simulator and V-Server Lite (versions prior to 4.0.10.0).

CVE-2020-10646 fujielectric vulnerability CVSS: 6.8 13 Apr 2020, 19:15 UTC

Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to read data, when parsing VPR files, is too small.

CVE-2019-18240 fujielectric vulnerability CVSS: 7.5 13 Nov 2019, 23:15 UTC

In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.

CVE-2019-13520 fujielectric vulnerability CVSS: 6.8 20 Aug 2019, 20:15 UTC

Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted project files to overflow the buffer and execute code under the privileges of the application.

CVE-2019-13512 fujielectric vulnerability CVSS: 4.3 15 Aug 2019, 19:15 UTC

Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an attacker to read limited information from the device.

CVE-2019-10975 fujielectric vulnerability CVSS: 3.3 02 Jul 2019, 20:15 UTC

An out-of-bounds read vulnerability has been identified in Fuji Electric Alpha7 PC Loader Versions 1.1 and prior, which may crash the system.

CVE-2019-3947 fujielectric vulnerability CVSS: 5.0 12 Jun 2019, 15:29 UTC

Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.

CVE-2019-3946 fujielectric vulnerability CVSS: 5.0 12 Jun 2019, 15:29 UTC

Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. An unauthenticated, remote attacker can crash vserver.exe due to an integer overflow in the UDP message handling logic.

CVE-2018-14812 fujielectric vulnerability CVSS: 6.8 24 Oct 2018, 21:29 UTC

An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Estimator versions V.1.0.2.0 and prior. Exploitation of this vulnerability could give an attacker access to the system with the same level of privilege as the application that utilizes the malicious DLL.

CVE-2018-14802 fujielectric vulnerability CVSS: 7.5 01 Oct 2018, 13:29 UTC

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does not properly check user-supplied comments which may allow for arbitrary remote code execution.

CVE-2018-14798 fujielectric vulnerability CVSS: 5.0 01 Oct 2018, 13:29 UTC

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does not properly parse FNC files that may allow for information disclosure.

CVE-2018-14794 fujielectric vulnerability CVSS: 7.5 01 Oct 2018, 13:29 UTC

Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the entire contents of the file to a heap-based buffer.

CVE-2018-14790 fujielectric vulnerability CVSS: 10.0 01 Oct 2018, 13:29 UTC

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.

CVE-2018-14788 fujielectric vulnerability CVSS: 5.0 01 Oct 2018, 13:29 UTC

Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. A buffer overflow information disclosure vulnerability occurs when parsing certain file types.

CVE-2018-14823 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

CVE-2018-14819 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution.

CVE-2018-14817 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.

CVE-2018-14815 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may allow remote code execution.

CVE-2018-14813 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.

CVE-2018-14811 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remote code execution.

CVE-2018-14809 fujielectric vulnerability CVSS: 7.5 26 Sep 2018, 20:29 UTC

Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote code execution.

CVE-2018-10637 fujielectric vulnerability CVSS: 6.8 13 Sep 2018, 19:29 UTC

A maliciously crafted project file may cause a buffer overflow, which may allow the attacker to execute arbitrary code that affects Fuji Electric V-Server Lite 4.0.3.0 and prior.

CVE-2018-5442 fujielectric vulnerability CVSS: 7.5 05 Feb 2018, 18:29 UTC

A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

CVE-2017-9662 fujielectric vulnerability CVSS: 4.6 14 Aug 2017, 16:29 UTC

An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could allow an authenticated attacker with local access to escalate privileges.

CVE-2017-9660 fujielectric vulnerability CVSS: 6.8 14 Aug 2017, 16:29 UTC

A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

CVE-2017-9659 fujielectric vulnerability CVSS: 6.8 14 Aug 2017, 16:29 UTC

A Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. The stack-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

CVE-2017-9639 fujielectric vulnerability CVSS: 7.5 17 Jul 2017, 19:29 UTC

An issue was discovered in Fuji Electric V-Server Version 3.3.22.0 and prior. A memory corruption vulnerability has been identified (aka improper restriction of operations within the bounds of a memory buffer), which may allow remote code execution.