CVE-2024-23608
- EPSS 1.44%
- Published 11.03.2024 16:15:07
- Last modified 21.11.2024 08:57:59
An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior ve...
CVE-2022-27237
- EPSS 0.5%
- Published 21.04.2022 05:15:06
- Last modified 21.11.2024 06:55:28
There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2...
CVE-2017-2779
- EPSS 0.62%
- Published 05.09.2017 18:29:00
- Last modified 20.04.2025 01:37:25
An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping c...
CVE-2017-2775
- EPSS 0.87%
- Published 31.03.2017 18:59:00
- Last modified 20.04.2025 01:37:25
An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabVIEW before 2015 SP1 f7 Patch and 2016 before f2 Patch. A specially crafted VI file can cause a user controlled value to be used as...
CVE-2013-5021
- EPSS 0.74%
- Published 06.08.2013 20:55:05
- Last modified 11.04.2025 00:51:21
Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager ...
CVE-2013-5023
- EPSS 0.5%
- Published 06.08.2013 20:55:05
- Last modified 11.04.2025 00:51:21
The ActiveX controls in the HelpAsst component in NI Help Links in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and other products allow remote attackers to cause a denial of service by triggering the displa...
- EPSS 1.4%
- Published 06.08.2013 20:55:05
- Last modified 11.04.2025 00:51:21
Absolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and other products allows remote attackers to create and execute arbitrar...