Skip to content
Noroxi

techsmith records

14 published records for vendor techsmith.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

14 records
  • MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso

    CriticalCVSS 9.8No exploitEPSS 3%

    techsmith · mp4v2Jul 19, 2018

  • A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.

    CriticalCVSS 9.8No exploitEPSS 3%

    techsmith · mp4v2Jul 13, 2018

  • CVE-2010-3130
    39Monitor

    Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exe

    CriticalCVSS 9.3Proof of conceptEPSS 8%

    techsmith · snagitAug 26, 2010

  • MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow

    HighCVSS 8.8No exploitEPSS 2%

    techsmith · mp4v2Jul 20, 2018

  • MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, w

    HighCVSS 8.8No exploitEPSS 2%

    techsmith · mp4v2Jul 18, 2018

  • In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.

    HighCVSS 8.8No exploitEPSS 2%

    techsmith · mp4v2Jul 16, 2018

  • In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.

    HighCVSS 8.8No exploitEPSS 2%

    techsmith · mp4v2Jul 16, 2018

  • TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to

    HighCVSS 8.8No exploitEPSS 0%

    techsmith · snagitJul 26, 2021

  • UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmit

    HighCVSS 7.8No exploitEPSS 2%

    techsmith · snagitJul 26, 2019

  • A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.

    HighCVSS 7.8No exploitEPSS 0%

    techsmith · snagitJul 26, 2021

  • CVE-2010-5234
    27Monitor

    Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)

    MediumCVSS 6.9No exploitEPSS 0%

    techsmith · camtasia studioSep 7, 2012

  • In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltra

    MediumCVSS 5.5No exploitEPSS 0%

    techsmith · snagitMay 8, 2020

  • CVE-2008-6061
    18Monitor

    Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia S

    MediumCVSS 4.3Proof of conceptEPSS 4%

    techsmith · camtasia studioFeb 4, 2009

  • CVE-2015-5487
    17Monitor

    Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows re

    MediumCVSS 4.3No exploitEPSS 1%

    techsmith · camtasia relayAug 18, 2015