← Vulnerability feed

Vulnerability record · CVE-2019-10951 · published 17 April 2019

CVE-2019-10951: Deltaww cncsoft screeneditor heap-based buffer overflow vulnerability

Deltaww · Cncsoft Screeneditor

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.

7.8 CVSS 3.1 High EPSS 2.9% · top 13.4% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 6.8
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/107989 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01 PatchThird Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-19-405/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-19-408/ Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/107989 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01 PatchThird Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-19-405/ Third Party AdvisoryVDB Entry
https://www.zerodayinitiative.com/advisories/ZDI-19-408/ Third Party AdvisoryVDB Entry

Track CVE-2019-10951 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22668Deltaww cncsoft screeneditor out-of-bounds read vulnerabilityDelta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds rea…EPSS 1.8%7.8CVE-2021-22672Deltaww cncsoft screeneditor out-of-bounds write vulnerabilityDelta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code exec…EPSS 9.0%7.8CVE-2020-27281Deltaww cncsoft screeneditor stack-based buffer overflow vulnerabilityA stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted projec…EPSS 2.0%7.8CVE-2020-16199Deltaww cncsoft screeneditor stack-based buffer overflow vulnerabilityDelta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited b…EPSS 9.5%7.8CVE-2020-16203Deltaww cncsoft screeneditor vulnerabilityDelta Industrial Automation CNCSoft ScreenEditor, Versions 1.01.23 and prior. An uninitialized pointer may be exploited by processing a specially cra…EPSS 1.9%7.8CVE-2020-7002Deltaww cncsoft screeneditor stack-based buffer overflow vulnerabilityDelta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens …EPSS 1.1%7.8CVE-2019-10947Deltaww cncsoft screeneditor stack-based buffer overflow vulnerabilityDelta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflow vulnerabilities may be expl…EPSS 3.7%5.5CVE-2021-44768Deltaww cncsoft screeneditor out-of-bounds read vulnerabilityDelta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may all…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2019-10951), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.