CVE-2011-4039: Dreamreport Dream Report
High severity, CVSS 9.3. EPSS: 4.1% chance of exploitation in the next 30 days.
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
Affected products
- Dreamreport Dream Report: up to and including 3.43; version 3.21 only; version 3.41 only; version 3.42 only
- Invensys Wonderware HMI Reports: up to and including 3.42.835.0304
Published 2012-02-10. Last modified 2026-06-16.