Hexagon's vulnerability footprint spans a small set of specialized geospatial, visualization, and video-management products including ERDAS ER Viewer, ERDAS Apollo, and Qognify VMS Client Viewer, serving niche sectors where these tools hold critical roles in analysis and monitoring workflows. The recurring weakness classes—buffer-boundary violations, SQL injection, and search-path manipulation—reflect the data-processing and file-handling demands of these visualization and command-execution contexts, and vulnerabilities in this vendor have a marked tendency to acquire public exploit tooling. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hexagon over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0726HIGH Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code | May 5, 2013 | 9.3 | 64 | NO | YES |
CVE-2013-3482HIGH Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or | Jan 19, 2014 | 9.3 | 59 | NO | YES |
CVE-2013-0728HIGH Multiple stack-based buffer overflows in NCSAddOn.dll in the ERDAS APOLLO ECWP plugin before 13.00.0001 for Internet Explorer, Firefox, and Chrome allow remote attackers to execute | Apr 25, 2013 | 10.0 | 26 | NO | NO |
CVE-2021-32051HIGH Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter. | May 14, 2021 | 7.5 | 25 | NO | NO |
CVE-2013-3483HIGH Stack-based buffer overflow in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (appli | Jan 19, 2014 | 9.3 | 24 | NO | NO |
CVE-2023-49114MEDIUM A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges | Feb 26, 2024 | 6.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hexagon.
Media articles that mention a CVE ID that affects a product developed by Hexagon — matched by CVE ID, not by vendor name.