Ezbsystems maintains a narrowly scoped product portfolio centered on UlralSO, a widely used ISO image manipulation utility that processes user-supplied file formats and binary data. The vendor's vulnerability profile is characterized by memory-safety weaknesses including buffer overflows, out-of-bounds writes, and format-string flaws that recur across its releases and frequently acquire public exploit code. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ezbsystems over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2888HIGH Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a r | May 30, 2007 | 7.6 | 70 | NO | YES |
CVE-2009-1260HIGH Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD | Apr 7, 2009 | 9.3 | 67 | NO | YES |
CVE-2008-4825HIGH Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) | Apr 1, 2009 | 9.3 | 24 | NO | NO |
CVE-2008-3871HIGH Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format str | Apr 1, 2009 | 9.3 | 23 | NO | NO |
CVE-2006-2099MEDIUM Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. | Apr 29, 2006 | 5.0 | 23 | NO | YES |
CVE-2018-25267MEDIUM UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handle | Apr 22, 2026 | 6.2 | 21 | NO | NO |
CVE-2017-2840HIGH A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in pot | Apr 24, 2018 | 7.8 | 21 | NO | NO |
CVE-2010-5255MEDIUM Untrusted search path vulnerability in UltraISO 9.3.6.2750 allows local users to gain privileges via a Trojan horse daemon.dll file in the current working directory, as demonstrate | Sep 7, 2012 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ezbsystems.
Media articles that mention a CVE ID that affects a product developed by Ezbsystems — matched by CVE ID, not by vendor name.