Edraw develops a suite of diagramming and visualization products, including viewer components for office documents, flowcharts, and PDFs, that are embedded in broader applications and deployed across business environments. The vendor's vulnerability pattern centers on memory-safety and code-execution weaknesses—buffer boundary violations, path-traversal conditions, and code-injection flaws—that recur across its viewer and ActiveX components and carry a strong tendency toward public exploit availability. Defenders tracking this vendor should prioritize patching its embedded viewers and restricting component usage where possible; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Edraw over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5257HIGH Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute | Oct 6, 2007 | 10.0 | 42 | NO | YES |
CVE-2007-3169HIGH Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause | Jun 11, 2007 | 9.3 | 38 | NO | YES |
CVE-2009-2169HIGH Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Component before 3.2.0.126 allows remote attackers to create and | Jun 22, 2009 | 9.3 | 37 | NO | YES |
CVE-2007-4821HIGH Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first a | Sep 11, 2007 | 9.3 | 37 | NO | YES |
CVE-2007-4420HIGH Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite | Aug 18, 2007 | 9.3 | 36 | NO | YES |
CVE-2007-5826HIGH Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitr | Nov 5, 2007 | 9.3 | 34 | NO | YES |
CVE-2007-3168HIGH A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files vi | Jun 11, 2007 | 7.8 | 31 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Edraw.
Media articles that mention a CVE ID that affects a product developed by Edraw — matched by CVE ID, not by vendor name.