Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2017-2840
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can provide a specific .ISO file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2010-5255
Disclosure Date: September 07, 2012 (last updated October 05, 2023)
Untrusted search path vulnerability in UltraISO 9.3.6.2750 allows local users to gain privileges via a Trojan horse daemon.dll file in the current working directory, as demonstrated by a directory that contains a .iso file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-1260
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.
0
Attacker Value
Unknown
CVE-2008-3871
Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format string specifiers in the filename of a (1) DAA or (2) ISZ file.
0
Attacker Value
Unknown
CVE-2008-4825
Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) C2D, or (3) GI file.
0
Attacker Value
Unknown
CVE-2007-2888
Disclosure Date: May 30, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-2099
Disclosure Date: April 29, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.
0