Coreldraw
Vendor:
First CVE: Aug 29, 2017 · Active for 8 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Coreldraw over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2017
8 years ago
Most Recent CVE
Mar 29, 2023
1,213 days ago
CVE Severity & Scoring
Coreldraw11 CVEs
36%
64%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (9.1%)
Unknown0 (0.0%)
Required10 (90.9%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None10 (90.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8393HIGH DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion. | Aug 29, 2017 | 7.8 | 32 | NO | YES |
CVE-2022-43618HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-43617HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-43616HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-43613HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 24 | NO | NO |
CVE-2016-9043HIGH An out of bound write vulnerability exists in the EMF parsing functionality of CorelDRAW X8 (CdrGfx - Corel Graphics Engine (64-Bit) - 18.1.0.661). A specially crafted EMF file can | Apr 24, 2018 | 7.8 | 22 | NO | NO |
CVE-2022-43615MEDIUM This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to | Mar 29, 2023 | 5.5 | 20 | NO | NO |
CVE-2022-43614HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 20 | NO | NO |
CVE-2022-43612MEDIUM This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to | Mar 29, 2023 | 5.5 | 19 | NO | NO |
CVE-2022-43611MEDIUM This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to | Mar 29, 2023 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Coreldraw
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| x8 | 1 | 7.8 | 2.7% | 0 | 0 |
| x7 | 1 | 7.8 | 8.3% | 0 | 1 |