Creative's vulnerability footprint centers on software auto-update mechanisms and associated components, including ActiveX controls and updater engines that manage application patching and lifecycle. The observed weakness classes reflect memory-safety challenges characteristic of native update infrastructure, primarily manifesting as buffer-boundary violations and related out-of-bounds access conditions.
The number and severity of CVEs published that impact products developed by Creative over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0955HIGH Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder prope | May 29, 2008 | 9.3 | 66 | NO | YES |
CVE-2010-0990HIGH Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arb | Jun 15, 2010 | 10.0 | 28 | NO | NO |
CVE-2021-38546MEDIUM CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowwor | Aug 11, 2021 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Creative.
Media articles that mention a CVE ID that affects a product developed by Creative — matched by CVE ID, not by vendor name.