CVE-2013-3928: Jpchacha Chasys Draw Ies
High severity, CVSS 9.3. EPSS: 37.2% chance of exploitation in the next 30 days.
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.
Affected products
- Jpchacha Chasys Draw Ies: up to and including 4.10.01; version 4.00.01 only; version 4.01.01 only; version 4.02.01 only; version 4.03.02 only; version 4.04.01 only; …
Published 2014-03-11. Last modified 2026-06-16.