nero records
9 published records for vendor nero.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-20 Improper Input Validation2
- CWE-189 Numeric Errors1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-428 Unquoted Search Path or Element1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2008-0619Proof of concept | Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause nero · mediaplayer · CWE-119 | Critical9.3 | — | 10.8% | Feb 6, 2008 |
39Monitor | CVE-2008-7079Proof of concept | Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vnero · showtime · CWE-119 | Critical9.3 | — | 5.8% | Aug 25, 2009 |
34Monitor | CVE-2025-63680No exploit | Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecnero · backitup · CWE-22 | High8.6 | — | 0.3% | Nov 14, 2025 |
32Monitor | CVE-2007-2322No exploit | NMMediaServer.exe in Nero MediaHome 2.5.5.0 and CE 1.3.0.4 allows remote attackers to cause a denial of service (NULL dereference and applicnero · mediahome · CWE-20 | High7.8 | — | 4.0% | Apr 26, 2007 |
31Monitor | CVE-2017-15383No exploit | Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGRAMFILES(x86)%\Nero dnero · nero · CWE-428 | High7.8 | — | 0.5% | Oct 16, 2017 |
22Monitor | CVE-2012-5877Proof of concept | Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP heanero · mediahome | Medium5.0 | — | 7.5% | May 30, 2014 |
21Monitor | CVE-2012-5876Proof of concept | Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of sernero · mediahome · CWE-189 | Medium5.0 | — | 4.3% | May 30, 2014 |
21Monitor | CVE-2008-1905No exploit | NMMediaServer.exe in Nero MediaHome 3.3.3.0 and earlier, as used in Nero 8.3.2.1 and earlier, allows remote attackers to cause a denial of snero · mediahome · CWE-20 | Medium5.0 | — | 2.2% | Apr 22, 2008 |
21Monitor | CVE-2005-3484No exploit | Directory traversal vulnerability in NeroNET 1.2.0.2 and earlier allows remote attackers to read arbitrary files with certain file extensionnero · neronet | Medium5.0 | — | 1.8% | Nov 3, 2005 |
- CVE-2008-061940Plan
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause
CriticalCVSS 9.3Proof of conceptEPSS 11%nero · mediaplayerFeb 6, 2008
- CVE-2008-707939Monitor
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code v
CriticalCVSS 9.3Proof of conceptEPSS 6%nero · showtimeAug 25, 2009
- CVE-2025-6368034Monitor
Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExec
HighCVSS 8.6No exploitEPSS 0%nero · backitupNov 14, 2025
- CVE-2007-232232Monitor
NMMediaServer.exe in Nero MediaHome 2.5.5.0 and CE 1.3.0.4 allows remote attackers to cause a denial of service (NULL dereference and applic
HighCVSS 7.8No exploitEPSS 4%nero · mediahomeApr 26, 2007
- CVE-2017-1538331Monitor
Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGRAMFILES(x86)%\Nero d
HighCVSS 7.8No exploitEPSS 0%nero · neroOct 16, 2017
- CVE-2012-587722Monitor
Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP hea
MediumCVSS 5.0Proof of conceptEPSS 7%nero · mediahomeMay 30, 2014
- CVE-2012-587621Monitor
Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of ser
MediumCVSS 5.0Proof of conceptEPSS 4%nero · mediahomeMay 30, 2014
- CVE-2008-190521Monitor
NMMediaServer.exe in Nero MediaHome 3.3.3.0 and earlier, as used in Nero 8.3.2.1 and earlier, allows remote attackers to cause a denial of s
MediumCVSS 5.0No exploitEPSS 2%nero · mediahomeApr 22, 2008
- CVE-2005-348421Monitor
Directory traversal vulnerability in NeroNET 1.2.0.2 and earlier allows remote attackers to read arbitrary files with certain file extension
MediumCVSS 5.0No exploitEPSS 2%nero · neronetNov 3, 2005