techsmith kayıtları
techsmith üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-704 Incorrect Type Conversion or Cast2
- CWE-269 Improper Privilege Management2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-190 Integer Overflow or Wraparound1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-14403İstismar yok | MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for assotechsmith · mp4v2 · CWE-704 | Kritik9,8 | — | %2,6 | 19 Tem 2018 |
40Planlayın | CVE-2018-14054İstismar yok | A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.techsmith · mp4v2 · CWE-415 | Kritik9,8 | — | %2,6 | 13 Tem 2018 |
39İzleyin | CVE-2010-3130Kavram kanıtı | Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exetechsmith · snagit | Kritik9,3 | — | %7,8 | 26 Ağu 2010 |
36İzleyin | CVE-2018-14446İstismar yok | MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow techsmith · mp4v2 · CWE-787 | Yüksek8,8 | — | %2,4 | 20 Tem 2018 |
36İzleyin | CVE-2018-14379İstismar yok | MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, wtechsmith · mp4v2 · CWE-704 | Yüksek8,8 | — | %2,2 | 18 Tem 2018 |
36İzleyin | CVE-2018-14325İstismar yok | In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.techsmith · mp4v2 · CWE-191 | Yüksek8,8 | — | %2,0 | 16 Tem 2018 |
36İzleyin | CVE-2018-14326İstismar yok | In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.techsmith · mp4v2 · CWE-190 | Yüksek8,8 | — | %1,9 | 16 Tem 2018 |
35İzleyin | CVE-2020-18171İstismar yok | TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to techsmith · snagit · CWE-269 | Yüksek8,8 | — | %0,4 | 26 Tem 2021 |
31İzleyin | CVE-2019-13382İstismar yok | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmittechsmith · snagit · CWE-59 | Yüksek7,8 | — | %1,6 | 26 Tem 2019 |
31İzleyin | CVE-2020-18169İstismar yok | A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.techsmith · snagit · CWE-269 | Yüksek7,8 | — | %0,5 | 26 Tem 2021 |
27İzleyin | CVE-2010-5234İstismar yok | Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)techsmith · camtasia studio | Orta6,9 | — | %0,5 | 7 Eyl 2012 |
22İzleyin | CVE-2020-11541İstismar yok | In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltratechsmith · snagit · CWE-611 | Orta5,5 | — | %0,3 | 8 May 2020 |
18İzleyin | CVE-2008-6061Kavram kanıtı | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Stechsmith · camtasia studio · CWE-79 | Orta4,3 | — | %4,1 | 4 Şub 2009 |
17İzleyin | CVE-2015-5487İstismar yok | Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows retechsmith · camtasia relay · CWE-79 | Orta4,3 | — | %1,2 | 18 Ağu 2015 |
- CVE-2018-1440340Planlayın
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso
KritikCVSS 9,8İstismar yokEPSS %3techsmith · mp4v219 Tem 2018
- CVE-2018-1405440Planlayın
A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0.
KritikCVSS 9,8İstismar yokEPSS %3techsmith · mp4v213 Tem 2018
- CVE-2010-313039İzleyin
Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to exe
KritikCVSS 9,3Kavram kanıtıEPSS %8techsmith · snagit26 Ağu 2010
- CVE-2018-1444636İzleyin
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow
YüksekCVSS 8,8İstismar yokEPSS %2techsmith · mp4v220 Tem 2018
- CVE-2018-1437936İzleyin
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, w
YüksekCVSS 8,8İstismar yokEPSS %2techsmith · mp4v218 Tem 2018
- CVE-2018-1432536İzleyin
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
YüksekCVSS 8,8İstismar yokEPSS %2techsmith · mp4v216 Tem 2018
- CVE-2018-1432636İzleyin
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.
YüksekCVSS 8,8İstismar yokEPSS %2techsmith · mp4v216 Tem 2018
- CVE-2020-1817135İzleyin
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to
YüksekCVSS 8,8İstismar yokEPSS %0techsmith · snagit26 Tem 2021
- CVE-2019-1338231İzleyin
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmit
YüksekCVSS 7,8İstismar yokEPSS %2techsmith · snagit26 Tem 2019
- CVE-2020-1816931İzleyin
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges.
YüksekCVSS 7,8İstismar yokEPSS %0techsmith · snagit26 Tem 2021
- CVE-2010-523427İzleyin
Multiple untrusted search path vulnerabilities in Camtasia Studio 7.0.1 build 57 allow local users to gain privileges via a Trojan horse (1)
OrtaCVSS 6,9İstismar yokEPSS %0techsmith · camtasia studio7 Eyl 2012
- CVE-2020-1154122İzleyin
In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltra
OrtaCVSS 5,5İstismar yokEPSS %0techsmith · snagit8 May 2020
- CVE-2008-606118İzleyin
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia S
OrtaCVSS 4,3Kavram kanıtıEPSS %4techsmith · camtasia studio4 Şub 2009
- CVE-2015-548717İzleyin
Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows re
OrtaCVSS 4,3İstismar yokEPSS %1techsmith · camtasia relay18 Ağu 2015