CVE-2024-10496
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
10/12/2024
Last modified:
04/03/2025
Description
An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:* | 2021 (including) | |
cpe:2.3:a:ni:labview:2022:q1:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2022:q3:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2022:q3_patch1:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2022:q3_patch2:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2023:q1:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2023:q3:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2023:q3_patch1:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2023:q3_patch2:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2023:q3_patch3:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2023:q3_patch4:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2024:q1:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2024:q1_patch1:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2024:q3:*:*:*:*:*:* | ||
cpe:2.3:a:ni:labview:2024:q3_patch1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page