Corel operates a moderately represented portfolio of consumer and professional creative applications, including CorelDRAW, Paint Shop Pro, and PDF Fusion, alongside Linux distributions. Vulnerabilities affecting the vendor recur through memory-safety and bounds-handling weakness classes—out-of-bounds reads and writes, integer overflows, and buffer-boundary violations—that reflect the native-code implementation typical of desktop graphics and document-processing software. The vendor's disclosures frequently acquire public exploit code, making timely patching important for users of affected applications. Defenders should prioritize updates for widely deployed instances of the creative suite, particularly in environments handling untrusted documents or user input; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Corel over time
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0742HIGH Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long ZIP directory ent | Oct 3, 2013 | 9.3 | 56 | NO | YES |
CVE-2013-3248HIGH Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonst | Oct 3, 2013 | 9.3 | 51 | NO | YES |
CVE-2007-2366HIGH Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file. | Apr 30, 2007 | 7.4 | 46 | NO | YES |
CVE-2009-4251HIGH Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: th | Dec 10, 2009 | 9.3 | 36 | NO | YES |
CVE-2007-1735HIGH Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a | Mar 28, 2007 | 9.3 | 36 | NO | YES |
CVE-2007-2209MEDIUM Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote | Apr 24, 2007 | 6.8 | 34 | NO | YES |
CVE-2014-8393HIGH DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion. | Aug 29, 2017 | 7.8 | 32 | NO | YES |
CVE-2009-2564HIGH NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products | Jul 21, 2009 | 7.2 | 31 | NO | YES |
CVE-2010-5240MEDIUM Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib | Sep 7, 2012 | 6.9 | 30 | NO | YES |
CVE-2013-0733HIGH Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attack | Jun 5, 2014 | 9.3 | 29 | NO | NO |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Corel.
Media articles that mention a CVE ID that affects a product developed by Corel — matched by CVE ID, not by vendor name.