techsmith records
14 published records for vendor techsmith.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-704 Incorrect Type Conversion or Cast2
- CWE-269 Improper Privilege Management2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-190 Integer Overflow or Wraparound1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-14403No exploit | MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for assotechsmith · mp4v2 · CWE-704 | Critical9.8 | — | 2.6% | Jul 19, 2018 |
40Plan | CVE-2018-14054No exploit | A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.techsmith · mp4v2 · CWE-415 | Critical9.8 | — | 2.6% | Jul 13, 2018 |
39Monitor | CVE-2010-3130Proof of concept | Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exetechsmith · snagit | Critical9.3 | — | 7.8% | Aug 26, 2010 |
36Monitor | CVE-2018-14446No exploit | MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow techsmith · mp4v2 · CWE-787 | High8.8 | — | 2.4% | Jul 20, 2018 |
36Monitor | CVE-2018-14379No exploit | MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, wtechsmith · mp4v2 · CWE-704 | High8.8 | — | 2.2% | Jul 18, 2018 |
36Monitor | CVE-2018-14325No exploit | In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.techsmith · mp4v2 · CWE-191 | High8.8 | — | 2.0% | Jul 16, 2018 |
36Monitor | CVE-2018-14326No exploit | In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.techsmith · mp4v2 · CWE-190 | High8.8 | — | 1.9% | Jul 16, 2018 |
35Monitor | CVE-2020-18171No exploit | TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to techsmith · snagit · CWE-269 | High8.8 | — | 0.4% | Jul 26, 2021 |
31Monitor | CVE-2019-13382No exploit | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmittechsmith · snagit · CWE-59 | High7.8 | — | 1.6% | Jul 26, 2019 |
31Monitor | CVE-2020-18169No exploit | A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.techsmith · snagit · CWE-269 | High7.8 | — | 0.5% | Jul 26, 2021 |
27Monitor | CVE-2010-5234No exploit | Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)techsmith · camtasia studio | Medium6.9 | — | 0.5% | Sep 7, 2012 |
22Monitor | CVE-2020-11541No exploit | In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltratechsmith · snagit · CWE-611 | Medium5.5 | — | 0.3% | May 8, 2020 |
18Monitor | CVE-2008-6061Proof of concept | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Stechsmith · camtasia studio · CWE-79 | Medium4.3 | — | 4.1% | Feb 4, 2009 |
17Monitor | CVE-2015-5487No exploit | Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows retechsmith · camtasia relay · CWE-79 | Medium4.3 | — | 1.2% | Aug 18, 2015 |
- CVE-2018-1440340Plan
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso
CriticalCVSS 9.8No exploitEPSS 3%techsmith · mp4v2Jul 19, 2018
- CVE-2018-1405440Plan
A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.
CriticalCVSS 9.8No exploitEPSS 3%techsmith · mp4v2Jul 13, 2018
- CVE-2010-313039Monitor
Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exe
CriticalCVSS 9.3Proof of conceptEPSS 8%techsmith · snagitAug 26, 2010
- CVE-2018-1444636Monitor
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow
HighCVSS 8.8No exploitEPSS 2%techsmith · mp4v2Jul 20, 2018
- CVE-2018-1437936Monitor
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, w
HighCVSS 8.8No exploitEPSS 2%techsmith · mp4v2Jul 18, 2018
- CVE-2018-1432536Monitor
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
HighCVSS 8.8No exploitEPSS 2%techsmith · mp4v2Jul 16, 2018
- CVE-2018-1432636Monitor
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.
HighCVSS 8.8No exploitEPSS 2%techsmith · mp4v2Jul 16, 2018
- CVE-2020-1817135Monitor
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to
HighCVSS 8.8No exploitEPSS 0%techsmith · snagitJul 26, 2021
- CVE-2019-1338231Monitor
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmit
HighCVSS 7.8No exploitEPSS 2%techsmith · snagitJul 26, 2019
- CVE-2020-1816931Monitor
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.
HighCVSS 7.8No exploitEPSS 0%techsmith · snagitJul 26, 2021
- CVE-2010-523427Monitor
Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)
MediumCVSS 6.9No exploitEPSS 0%techsmith · camtasia studioSep 7, 2012
- CVE-2020-1154122Monitor
In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltra
MediumCVSS 5.5No exploitEPSS 0%techsmith · snagitMay 8, 2020
- CVE-2008-606118Monitor
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia S
MediumCVSS 4.3Proof of conceptEPSS 4%techsmith · camtasia studioFeb 4, 2009
- CVE-2015-548717Monitor
Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows re
MediumCVSS 4.3No exploitEPSS 1%techsmith · camtasia relayAug 18, 2015