Lattice Semiconductor's vulnerability profile centers on a narrow product line focused on FPGA design and programming tools, including Diamond Programmer and PAC Designer, which serve embedded and hardware-development contexts. The observed disclosures cluster around memory-buffer boundary violations, reflecting the low-level access patterns inherent to firmware and hardware-design tooling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lattice Semiconductor over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2915HIGH Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematic | May 21, 2012 | 9.3 | 61 | NO | YES |
CVE-2012-2614MEDIUM Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application crash) and execute arbitrary c | Jul 12, 2012 | 6.8 | 31 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lattice Semiconductor.
Media articles that mention a CVE ID that affects a product developed by Lattice Semiconductor — matched by CVE ID, not by vendor name.