Sweetscape's vulnerability profile centers on 010 Editor, a specialized binary-analysis and hex-editing tool deployed in security research, reverse engineering, and software development workflows. Vulnerabilities affecting the product skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around memory-safety issues including out-of-bounds reads and writes, integer overflows, and related parsing defects that are characteristic of tools that parse untrusted binary formats. Defenders relying on this tool in security-critical contexts should track updates closely; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sweetscape over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12553CRITICAL In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to over | Jun 5, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-12555HIGH In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (provided by the scripting engine) allows an attacker to caus | Jun 5, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-12554HIGH In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cau | Jun 5, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-12551MEDIUM In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to over | Jul 22, 2019 | 5.5 | 21 | NO | NO |
CVE-2010-5229MEDIUM Untrusted search path vulnerability in 010 Editor before 3.1.3 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demon | Sep 7, 2012 | 6.9 | 21 | NO | NO |
CVE-2019-12552MEDIUM In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service. | Jul 22, 2019 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sweetscape.
Media articles that mention a CVE ID that affects a product developed by Sweetscape — matched by CVE ID, not by vendor name.