Filtered by vendor Corel
Subscribe
Total
54 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2014-8393 | 1 Corel | 5 Coreldraw, Coreldraw Photo Paint, Paint Shop Pro and 2 more | 2025-04-20 | 4.6 MEDIUM | 7.8 HIGH |
|
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
|
|||||
| CVE-2022-46662 | 1 Corel | 1 Roxio Creator Ljb | 2025-04-16 | N/A | 6.7 MEDIUM |
|
Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service. The affected product and versions are as follows: Roxio Creator LJB version number 12.2 build number 106B62B, version number 12.2 build number 106B63A, version number 12.2 build number 106B69A, version number 12.2 build number 1 ...
Show More |
|||||
| CVE-2014-8397 | 1 Corel | 2 Fastflick, Videostudio Pro | 2025-04-12 | 4.6 MEDIUM | N/A |
|
Untrusted search path vulnerability in Corel VideoStudio PRO X7 or FastFlick allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse u32ZLib.dll file that is located in the same folder as the file being processed.
|
|||||
| CVE-2014-8395 | 1 Corel | 1 Painter | 2025-04-12 | 4.6 MEDIUM | N/A |
|
Untrusted search path vulnerability in Corel Painter 2015 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wacommt.dll file that is located in the same folder as the file being processed.
|
|||||
| CVE-2014-8394 | 1 Corel | 1 Corelcad | 2025-04-12 | 4.6 MEDIUM | N/A |
|
Multiple untrusted search path vulnerabilities in Corel CAD 2014 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) FxManagedCommands_3.08_9.tx or (2) TD_Mgd_3.08_9.dll file in the current working directory.
|
|||||
| CVE-2015-6948 | 1 Corel | 1 Wordperfect | 2025-04-12 | 6.8 MEDIUM | N/A |
|
Heap-based buffer overflow in the Microsoft Word document conversion feature in Corel WordPerfect allows remote attackers to execute arbitrary code via a crafted document.
|
|||||
| CVE-2014-8398 | 1 Corel | 1 Fastflick | 2025-04-12 | 4.6 MEDIUM | N/A |
|
Multiple untrusted search path vulnerabilities in Corel FastFlick allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) igfxcmrt32.dll, (2) ipl.dll, (3) MSPStyleLib.dll, (4) uFioUtil.dll, (5) uhDSPlay.dll, (6) uipl.dll, (7) uvipl.dll, (8) VC1DecDll.dll, or (9) VC1DecDll_SSE3.dll file that is located in the same folder as the file being processed.
|
|||||
| CVE-2014-8396 | 1 Corel | 1 Pdf Fusion | 2025-04-12 | 4.6 MEDIUM | N/A |
|
Untrusted search path vulnerability in Corel PDF Fusion allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll file that is located in the same folder as the file being processed.
|
|||||
| CVE-2013-0733 | 1 Corel | 2 Paintshop Pro X5, Paintshop Pro X6 | 2025-04-12 | 9.3 HIGH | N/A |
|
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jpg file.
|
|||||
| CVE-2012-4728 | 1 Corel | 1 Quattro Pro X6 | 2025-04-12 | 4.3 MEDIUM | N/A |
|
The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition 16.0.0.388 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted QPW file.
|
|||||
| CVE-2013-0742 | 1 Corel | 1 Pdf Fusion | 2025-04-11 | 9.3 HIGH | N/A |
|
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long ZIP directory entry name in an XPS file.
|
|||||
| CVE-2013-3248 | 1 Corel | 1 Pdf Fusion | 2025-04-11 | 9.3 HIGH | N/A |
|
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.
|
|||||
| CVE-2010-5240 | 1 Corel | 2 Coreldraw X5, Photo-paint X3 | 2025-04-11 | 6.9 MEDIUM | N/A |
|
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib.dll file in the current working directory, as demonstrated by a directory that contains a .cdr, .cpt, .cmx, or .csl file. NOTE: some of these details are obtained from third party information.
|
|||||
| CVE-2009-4251 | 1 Corel | 1 Paint Shop Pro | 2025-04-09 | 9.3 HIGH | N/A |
|
Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.
|
|||||
| CVE-2007-2209 | 2 Accusoft, Corel | 2 Imagegear, Paint Shop Pro | 2025-04-09 | 6.8 MEDIUM | N/A |
|
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file. NOTE: some details were obtained from third party sources.
|
|||||
| CVE-2009-2564 | 3 Adobe, Corel, Nos Microsystems | 3 Acrobat Reader, Getplus Download Manager, Getplus Download Manager | 2025-04-09 | 7.2 HIGH | N/A |
|
NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of t ...
Show More |
|||||
| CVE-2007-1735 | 1 Corel | 1 Wordperfect | 2025-04-09 | 9.3 HIGH | N/A |
|
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.
|
|||||
| CVE-2007-2366 | 1 Corel | 1 Paint Shop Pro | 2025-04-09 | 7.4 HIGH | N/A |
|
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
|
|||||
| CVE-2007-2921 | 1 Corel | 1 Activecgm Browser | 2025-04-09 | 9.3 HIGH | N/A |
|
Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.
|
|||||
| CVE-2000-0048 | 1 Corel | 1 Linux | 2025-04-03 | 7.2 HIGH | N/A |
|
get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.
|
|||||
| CVE-2000-0193 | 1 Corel | 1 Linux | 2025-04-03 | 7.2 HIGH | N/A |
|
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.
|
|||||
| CVE-2000-0194 | 1 Corel | 1 Linux | 2025-04-03 | 7.2 HIGH | N/A |
|
buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.
|
|||||
| CVE-2000-0195 | 1 Corel | 1 Linux | 2025-04-03 | 7.2 HIGH | N/A |
|
setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.
|
|||||
| CVE-1999-1173 | 1 Corel | 1 Wordperfect | 2025-04-03 | 2.1 LOW | N/A |
|
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.
|
|||||
| CVE-2022-43618 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 7.8 HIGH |
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage thi ...
Show More |
|||||
| CVE-2022-43617 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 7.8 HIGH |
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage thi ...
Show More |
|||||
| CVE-2022-43616 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 7.8 HIGH |
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage thi ...
Show More |
|||||
| CVE-2022-43615 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 5.5 MEDIUM |
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can lever ...
Show More |
|||||
| CVE-2022-43614 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 7.8 HIGH |
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF images. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage th ...
Show More |
|||||
| CVE-2022-43613 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 7.8 HIGH |
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. When parsing CGM files, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage thi ...
Show More |
|||||
| CVE-2022-43612 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 5.5 MEDIUM |
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leve ...
Show More |
|||||
| CVE-2022-43611 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 5.5 MEDIUM |
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of BMP images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leve ...
Show More |
|||||
| CVE-2022-43610 | 1 Corel | 1 Coreldraw | 2024-11-21 | N/A | 5.5 MEDIUM |
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leve ...
Show More |
|||||
| CVE-2021-38110 | 1 Corel | 1 Wordperfect 2020 | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious DOC file.
|
|||||
| CVE-2021-38109 | 1 Corel | 1 Coreldraw 2020 | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious CDR file.
|
|||||
| CVE-2021-38108 | 1 Corel | 1 Wordperfect 2020 | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious DOC file.
|
|||||
| CVE-2021-38107 | 1 Corel | 1 Coreldraw 2020 | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
CdrCore.dll in Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious CDR file.
|
|||||
| CVE-2021-38106 | 1 Corel | 1 Presentations 2020 | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
UAX200.dll in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PPT file.
|
|||||
| CVE-2021-38105 | 1 Corel | 1 Presentations 2020 | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
IPPP82.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PPT file. This is different from CVE-2021-38102.
|
|||||
| CVE-2021-38104 | 1 Corel | 1 Presentations 2020 | 2024-11-21 | 4.3 MEDIUM | 5.5 MEDIUM |
|
IPPP72.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PPT file.
|
|||||