An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ni
Ni labview |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* cpe:2.3:a:ni:labview:2022:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2022:q3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2022:q3_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2022:q3_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2023:q3_patch4:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q1_patch1:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3:*:*:*:*:*:* cpe:2.3:a:ni:labview:2024:q3_patch1:*:*:*:*:*:* |
|
| Vendors & Products |
Ni
Ni labview |
Tue, 10 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Dec 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions. | |
| Title | Out of bounds read when loading the font table in fontmgr.cpp in NI LabVIEW | |
| Weaknesses | CWE-1285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NI
Published: 2024-12-10T15:52:43.177Z
Updated: 2024-12-10T20:18:12.830Z
Reserved: 2024-10-29T14:41:27.738Z
Link: CVE-2024-10495
Updated: 2024-12-10T20:18:08.572Z
Status : Analyzed
Published: 2024-12-10T16:15:22.080
Modified: 2025-03-04T18:19:12.327
Link: CVE-2024-10495
No data.