cbcvebase.

Siemens Jt2Go vulnerabilities

169 known vulnerabilities affecting siemens/jt2go.

Total CVEs
169
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH123MEDIUM43LOW3

Vulnerabilities

Page 6 of 9
CVE-2020-26981P3MEDIUMCVSS 6.5fixed in 13.1.0vAll versions < V13.1.02021-01-12
CVE-2020-26981 [MEDIUM] CWE-611 CVE-2020-26981: A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restric
nvd
CVE-2022-3159P3HIGHCVSS 7.8fixed in 14.1.0.52023-01-13
CVE-2022-3159 [HIGH] CWE-121 CVE-2022-3159: The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while pa The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2022-2069P3HIGHCVSS 7.8fixed in 13.3.0.5≥ unspecified, < V13.3.0.52022-10-20
CVE-2022-2069 [HIGH] CWE-122 CVE-2022-2069: The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14. The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2022-3161P3HIGHCVSS 7.8fixed in 14.1.0.52023-01-13
CVE-2022-3161 [HIGH] CWE-119 CVE-2022-3161: The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF file The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2022-41661P3HIGHCVSS 7.8fixed in 14.1.0.4vAll versions < V14.1.0.42022-11-08
CVE-2022-41661 [HIGH] CWE-125 CVE-2022-41661: A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V14.0 (All versions < V14.0.0.3), Teamcenter Visualization V14.1 (All versions < V14.1.0.4). The affected products contain an out of boun
nvd
CVE-2022-41662P3HIGHCVSS 7.8fixed in 14.1.0.4vAll versions < V14.1.0.42022-11-08
CVE-2022-41662 [HIGH] CWE-125 CVE-2022-41662: A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V14.0 (All versions < V14.0.0.3), Teamcenter Visualization V14.1 (All versions < V14.1.0.4). The affected products contain an out of boun
nvd
CVE-2022-41283P3HIGHCVSS 7.8vAll versions < V14.1.0.62022-12-13
CVE-2022-41283 [HIGH] CWE-787 CVE-2022-41283: A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V1 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of
nvd
CVE-2022-41281P3HIGHCVSS 7.8vAll versions < V14.1.0.62022-12-13
CVE-2022-41281 [HIGH] CWE-125 CVE-2022-41281: A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V1 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of
nvd
CVE-2022-41284P3HIGHCVSS 7.8vAll versions < V14.1.0.62022-12-13
CVE-2022-41284 [HIGH] CWE-125 CVE-2022-41284: A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V1 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of
nvd
CVE-2022-41282P3HIGHCVSS 7.8vAll versions < V14.1.0.62022-12-13
CVE-2022-41282 [HIGH] CWE-125 CVE-2022-41282: A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V1 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of
nvd
CVE-2022-41286P3HIGHCVSS 7.8vAll versions < V14.1.0.62022-12-13
CVE-2022-41286 [HIGH] CWE-125 CVE-2022-41286: A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V1 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGM_NIST_Loader.dll contains an out of
nvd
CVE-2022-45484P3HIGHCVSS 7.8vAll versions < V14.1.0.62022-12-13
CVE-2022-45484 [HIGH] CWE-125 CVE-2022-45484: A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V1 A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.9), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.5), Teamcenter Visualization V14.0 (All version
nvd
CVE-2023-7066P3HIGHCVSS 7.8fixed in V14.3.0.82024-08-12
CVE-2023-7066 [HIGH] CWE-125 CVE-2023-7066: The affected applications contain an out of bounds read past the end of an allocated structure whil The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2022-3160P3HIGHCVSS 7.8fixed in 14.1.0.52023-01-13
CVE-2022-3160 [HIGH] CWE-122 CVE-2022-3160: The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsin The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2023-1709P3HIGHCVSS 7.8fixed in 14.2.0.22023-06-07
CVE-2023-1709 [HIGH] CWE-121 CVE-2023-1709: Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.
nvd
CVE-2020-27002P3HIGHCVSS 7.1fixed in 13.1.0.2vAll versions < V13.1.0.22021-02-09
CVE-2020-27002 [HIGH] CWE-125 CVE-2020-27002: A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (A A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a memory access past the end of an allocated buffer. An attacker could leverage this vulnerability to access dat
nvd
CVE-2021-25175P3HIGHCVSS 7.8fixed in 13.1.0.12021-01-18
CVE-2021-25175 [HIGH] CWE-704 CVE-2021-25175: An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
nvd
CVE-2021-25177P4HIGHCVSS 7.8fixed in 13.1.0.12021-01-18
CVE-2021-25177 [HIGH] CWE-843 CVE-2021-25177: An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
nvd
CVE-2021-25176P4HIGHCVSS 7.8fixed in 13.1.0.12021-01-18
CVE-2021-25176 [HIGH] CWE-476 CVE-2021-25176: An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer derefere An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
nvd
CVE-2021-25173P4HIGHCVSS 7.8fixed in 13.1.0.12021-01-18
CVE-2021-25173 [HIGH] CWE-770 CVE-2021-25173: An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation wit An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
nvd
Siemens Jt2Go vulnerabilities | cvebase