Show filters
56 Total Results
Displaying 41-50 of 56
Sort by:
Attacker Value
Unknown
CVE-2013-0733
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jpg file.
0
Attacker Value
Unknown
CVE-2012-4728
Disclosure Date: June 05, 2014 (last updated October 05, 2023)
The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition 16.0.0.388 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted QPW file.
0
Attacker Value
Unknown
CVE-2013-0742
Disclosure Date: October 03, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long ZIP directory entry name in an XPS file.
0
Attacker Value
Unknown
CVE-2013-3248
Disclosure Date: October 03, 2013 (last updated October 05, 2023)
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.
0
Attacker Value
Unknown
CVE-2010-5240
Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib.dll file in the current working directory, as demonstrated by a directory that contains a .cdr, .cpt, .cmx, or .csl file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-4251
Disclosure Date: December 10, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.
0
Attacker Value
Unknown
CVE-2009-2564
Disclosure Date: July 21, 2009 (last updated October 04, 2023)
NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.
0
Attacker Value
Unknown
CVE-2007-2921
Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-2366
Disclosure Date: April 30, 2007 (last updated October 04, 2023)
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
0
Attacker Value
Unknown
CVE-2007-2209
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file. NOTE: some details were obtained from third party sources.
0