Cyberlink develops a focused line of multimedia authoring and playback software, including products such as PowerDirector, PowerDVD, and related utilities that target consumer and prosumer content creation and management. The vendor's vulnerability disclosures cluster around memory-safety and access-control weaknesses—buffer-boundary violations, path-traversal conditions, and improper privilege management—typical of desktop applications that handle file I/O and user permissions, and frequently acquire public exploit code. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyberlink over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5171HIGH Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameter | Sep 15, 2012 | 9.3 | 71 | NO | YES |
CVE-2017-14627HIGH Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFO | Sep 23, 2017 | 7.8 | 54 | NO | YES |
CVE-2007-5219MEDIUM Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote atta | Oct 5, 2007 | 6.4 | 32 | NO | YES |
CVE-2022-29333HIGH A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file. | May 24, 2022 | 7.8 | 28 | NO | NO |
CVE-2010-5243MEDIUM Multiple untrusted search path vulnerabilities in Cyberlink Power2Go 7.0.0.0816 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) MFC71LOC.DLL file in t | Sep 7, 2012 | 6.9 | 21 | NO | NO |
CVE-2012-4758MEDIUM Multiple untrusted search path vulnerabilities in CyberLink PowerProducer 5.5.3.2325 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll fi | Sep 6, 2012 | 6.9 | 21 | NO | NO |
CVE-2012-4757MEDIUM Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll | Sep 6, 2012 | 6.9 | 21 | NO | NO |
CVE-2012-4756MEDIUM Multiple untrusted search path vulnerabilities in CyberLink LabelPrint 2.5.3602 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in | Sep 6, 2012 | 6.9 | 21 | NO | NO |
CVE-2010-5238MEDIUM Untrusted search path vulnerability in CyberLink PowerDirector 8.00.3022 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, | Sep 7, 2012 | 6.9 | 20 | NO | NO |
CVE-2010-5237MEDIUM Untrusted search path vulnerability in CyberLink PowerDirector 7 allows local users to gain privileges via a Trojan horse mfc71loc.dll file in the current working directory, as dem | Sep 7, 2012 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyberlink.
Media articles that mention a CVE ID that affects a product developed by Cyberlink — matched by CVE ID, not by vendor name.