Записи techsmith
14 опубликованных записей вендора techsmith.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-704 Incorrect Type Conversion or Cast2
- CWE-269 Improper Privilege Management2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-190 Integer Overflow or Wraparound1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-14403Эксплойта нет | MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for assotechsmith · mp4v2 · CWE-704 | Критическая9,8 | — | 2,6 % | 19 июл. 2018 г. |
40В плане | CVE-2018-14054Эксплойта нет | A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.techsmith · mp4v2 · CWE-415 | Критическая9,8 | — | 2,6 % | 13 июл. 2018 г. |
39Наблюдать | CVE-2010-3130Proof of concept | Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exetechsmith · snagit | Критическая9,3 | — | 7,8 % | 26 авг. 2010 г. |
36Наблюдать | CVE-2018-14446Эксплойта нет | MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow techsmith · mp4v2 · CWE-787 | Высокая8,8 | — | 2,4 % | 20 июл. 2018 г. |
36Наблюдать | CVE-2018-14379Эксплойта нет | MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, wtechsmith · mp4v2 · CWE-704 | Высокая8,8 | — | 2,2 % | 18 июл. 2018 г. |
36Наблюдать | CVE-2018-14325Эксплойта нет | In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.techsmith · mp4v2 · CWE-191 | Высокая8,8 | — | 2,0 % | 16 июл. 2018 г. |
36Наблюдать | CVE-2018-14326Эксплойта нет | In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.techsmith · mp4v2 · CWE-190 | Высокая8,8 | — | 1,9 % | 16 июл. 2018 г. |
35Наблюдать | CVE-2020-18171Эксплойта нет | TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to techsmith · snagit · CWE-269 | Высокая8,8 | — | 0,4 % | 26 июл. 2021 г. |
31Наблюдать | CVE-2019-13382Эксплойта нет | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmittechsmith · snagit · CWE-59 | Высокая7,8 | — | 1,6 % | 26 июл. 2019 г. |
31Наблюдать | CVE-2020-18169Эксплойта нет | A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.techsmith · snagit · CWE-269 | Высокая7,8 | — | 0,5 % | 26 июл. 2021 г. |
27Наблюдать | CVE-2010-5234Эксплойта нет | Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)techsmith · camtasia studio | Средняя6,9 | — | 0,5 % | 7 сент. 2012 г. |
22Наблюдать | CVE-2020-11541Эксплойта нет | In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltratechsmith · snagit · CWE-611 | Средняя5,5 | — | 0,3 % | 8 мая 2020 г. |
18Наблюдать | CVE-2008-6061Proof of concept | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Stechsmith · camtasia studio · CWE-79 | Средняя4,3 | — | 4,1 % | 4 февр. 2009 г. |
17Наблюдать | CVE-2015-5487Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows retechsmith · camtasia relay · CWE-79 | Средняя4,3 | — | 1,2 % | 18 авг. 2015 г. |
- CVE-2018-1440340В плане
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %techsmith · mp4v219 июл. 2018 г.
- CVE-2018-1405440В плане
A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %techsmith · mp4v213 июл. 2018 г.
- CVE-2010-313039Наблюдать
Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exe
КритическаяCVSS 9,3Proof of conceptEPSS 8 %techsmith · snagit26 авг. 2010 г.
- CVE-2018-1444636Наблюдать
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %techsmith · mp4v220 июл. 2018 г.
- CVE-2018-1437936Наблюдать
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, w
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %techsmith · mp4v218 июл. 2018 г.
- CVE-2018-1432536Наблюдать
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %techsmith · mp4v216 июл. 2018 г.
- CVE-2018-1432636Наблюдать
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %techsmith · mp4v216 июл. 2018 г.
- CVE-2020-1817135Наблюдать
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %techsmith · snagit26 июл. 2021 г.
- CVE-2019-1338231Наблюдать
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmit
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %techsmith · snagit26 июл. 2019 г.
- CVE-2020-1816931Наблюдать
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %techsmith · snagit26 июл. 2021 г.
- CVE-2010-523427Наблюдать
Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)
СредняяCVSS 6,9Эксплойта нетEPSS 0 %techsmith · camtasia studio7 сент. 2012 г.
- CVE-2020-1154122Наблюдать
In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltra
СредняяCVSS 5,5Эксплойта нетEPSS 0 %techsmith · snagit8 мая 2020 г.
- CVE-2008-606118Наблюдать
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia S
СредняяCVSS 4,3Proof of conceptEPSS 4 %techsmith · camtasia studio4 февр. 2009 г.
- CVE-2015-548717Наблюдать
Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows re
СредняяCVSS 4,3Эксплойта нетEPSS 1 %techsmith · camtasia relay18 авг. 2015 г.