Vulnerability Details CVE-2023-27916
The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.4%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-27916
-
cpe:2.3:a:hornerautomation:cscape:9.90
-
cpe:2.3:a:hornerautomation:cscape_envisionrv:4.70