Acdsystems develops a focused suite of image editing and asset management applications including Canvas Draw, ACDSee, and Photo Editor, where reported vulnerabilities cluster around memory-handling issues such as out-of-bounds writes and heap-based buffer overflows. These weakness classes are typical of native image-processing codebases and arise from the parsing demands of complex file formats; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acdsystems over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2193HIGH Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitr | Apr 24, 2007 | 9.3 | 62 | NO | YES |
CVE-2007-1943HIGH Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a cr | Apr 11, 2007 | 9.3 | 37 | NO | YES |
CVE-2012-1197HIGH Integer overflow in the IDE_ACDStd.apl module for ACDSee 14.1 Build 137 allows remote attackers to execute arbitrary code via crafted "image dimension values" in a BMP file, which | Feb 18, 2012 | 9.3 | 28 | NO | NO |
CVE-2018-3870HIGH An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an | Jul 19, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-3871HIGH An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially crafted PCX image processed via the application can lead to an | Jul 19, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3859HIGH An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to a | Jul 19, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3858HIGH An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out- | Jul 19, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3857HIGH An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out- | Jul 19, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-3860HIGH An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to a | Jul 19, 2018 | 7.8 | 24 | NO | NO |
CVE-2002-1756MEDIUM ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties | Dec 31, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acdsystems.
Media articles that mention a CVE ID that affects a product developed by Acdsystems — matched by CVE ID, not by vendor name.