Ollydbg is a specialized reverse-engineering and debugging tool with a narrow product scope, though it maintains prominence among security researchers and analysts who rely on it for binary instrumentation and malware analysis. The limited vulnerability surface centers on the core debugger application and reflects memory-safety issues including buffer-boundary violations, typical of native code tools that perform low-level process inspection and manipulation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ollydbg over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0733HIGH Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are d | Jul 27, 2004 | 7.5 | 30 | NO | YES |
CVE-2008-3148MEDIUM Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file that contains a long string. | Jul 11, 2008 | 6.8 | 29 | NO | YES |
CVE-2024-11495HIGH Buffer overflow vulnerability in OllyDbg, version 1.10, which could allow a local attacker to execute arbitrary code due to lack of proper bounds checking. | Nov 20, 2024 | 7.8 | 22 | NO | NO |
CVE-2005-0826MEDIUM OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename. | May 2, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ollydbg.
Media articles that mention a CVE ID that affects a product developed by Ollydbg — matched by CVE ID, not by vendor name.