Accusoft develops document and image-processing software positioned in content-conversion and document-management workflows, with a narrow but high-value product portfolio centered on ImageGear, PrizmDoc, and Prizm Content Connect. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the inherent risks of parsing and buffer manipulation in media-processing codebases. The exposure recurs consistently through memory-safety weakness classes—out-of-bounds writes, heap-based buffer overflows, buffer-size calculation errors, and improper array-index validation—that are characteristic of native image-parsing implementations handling untrusted input. Defenders should treat this vendor's updates as high-priority for environments where document conversion or embedded imaging sits at the network boundary or processes untrusted files. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accusoft over time
Signals from CVEs in this vendor scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5190CRITICAL Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability | Jan 21, 2020 | 9.8 | 42 | NO | YES |
CVE-2007-2209MEDIUM Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote | Apr 24, 2007 | 6.8 | 34 | NO | YES |
CVE-2021-21821CRITICAL A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to code executi | Jul 8, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21833CRITICAL An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to | Jun 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21795CRITICAL A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integ | Jun 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-6151CRITICAL A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7. A specially crafted malformed file can cause a memory cor | Sep 1, 2020 | 9.8 | 31 | NO | NO |
CVE-2023-35002CRITICAL A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution | Sep 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-29465CRITICAL An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-21824CRITICAL An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An | Jun 11, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-15805CRITICAL Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service ( | Dec 10, 2018 | 9.1 | 30 | NO | NO |
Signals from CVEs in this vendor scope (61 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accusoft.
Media articles that mention a CVE ID that affects a product developed by Accusoft — matched by CVE ID, not by vendor name.