CVE-2025-49850 is a high-severity vulnerability in LS Electric GMWin 4 that CISA published on 2025-06-17. The issue is a heap-based buffer overflow in PRJ file parsing caused by insufficient validation of user-supplied data. According to the advisory, this can lead to memory corruption, including reading and writing past the end of allocated data structures. The affected product listed in the advisory is [truncated]
CVE-2025-49849 is a high-severity vulnerability in LS Electric GMWin 4 that affects parsing of PRJ files. CISA’s advisory describes an out-of-bounds read caused by insufficient validation of user-supplied data, with the potential for memory corruption and reads or writes past allocated data structures. The advisory lists GMWin 4 version 4.18 as affected and notes the product has been discontinued, with LS [truncated]
CVE-2025-49848 is a high-severity memory corruption issue in LS Electric GMWin 4, specifically in PRJ file parsing. The advisory says inadequate validation of user-supplied data can lead to out-of-bounds reads and writes, which raises the risk of application instability and possible denial of service or other memory corruption effects. The supplied CISA advisory lists GMWin 4: 4.18 as affected and notes t [truncated]