winimage records
5 published records for vendor winimage.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2007-4962Proof of concept | Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files winimage · winimage · CWE-22 | Critical9.3 | — | 6.0% | Sep 18, 2007 |
39Monitor | CVE-2007-2758No exploit | Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains winimage · winimage | Critical9.3 | — | 5.7% | May 18, 2007 |
38Monitor | CVE-2007-4963No exploit | Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of winimage · winimage | Critical9.3 | — | 2.0% | Sep 18, 2007 |
27Monitor | CVE-2010-5253No exploit | Untrusted search path vulnerability in WinImage 8.50 allows local users to gain privileges via a Trojan horse wnaspi32.dll file in the currewinimage · winimage | Medium6.9 | — | 0.5% | Sep 7, 2012 |
21Monitor | CVE-2007-4964Proof of concept | WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the hewinimage · winimage · CWE-20 | Medium5.0 | — | 2.8% | Sep 18, 2007 |
- CVE-2007-496239Monitor
Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files
CriticalCVSS 9.3Proof of conceptEPSS 6%winimage · winimageSep 18, 2007
- CVE-2007-275839Monitor
Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains
CriticalCVSS 9.3No exploitEPSS 6%winimage · winimageMay 18, 2007
- CVE-2007-496338Monitor
Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of
CriticalCVSS 9.3No exploitEPSS 2%winimage · winimageSep 18, 2007
- CVE-2010-525327Monitor
Untrusted search path vulnerability in WinImage 8.50 allows local users to gain privileges via a Trojan horse wnaspi32.dll file in the curre
MediumCVSS 6.9No exploitEPSS 1%winimage · winimageSep 7, 2012
- CVE-2007-496421Monitor
WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the he
MediumCVSS 5.0Proof of conceptEPSS 3%winimage · winimageSep 18, 2007