PowerISO is a disk image and optical media utility with a narrow product portfolio focused on ISO file creation, mounting, and manipulation. Vulnerabilities affecting the product center on memory-safety issues, including out-of-bounds writes, buffer-boundary violations, and use-after-free conditions, reflecting the low-level file parsing and image-handling complexity inherent to media-utility software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Poweriso over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2102HIGH Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image. | Apr 29, 2006 | 7.8 | 32 | NO | YES |
CVE-2017-2823HIGH A use-after-free vulnerability exists in the .ISO parsing functionality of PowerISO 6.8. A specially crafted .ISO file can cause a vulnerability resulting in potential code executi | May 24, 2017 | 7.8 | 29 | NO | NO |
CVE-2022-41992HIGH A memory corruption vulnerability exists in the VHD File Format parsing CXSPARSE record functionality of PowerISO PowerISO 8.3. A specially-crafted file can lead to an out-of-bound | Dec 16, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-21871HIGH A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially crafted DMG file can lead to an out-of-bounds write. An attacker | Jun 29, 2021 | 7.8 | 25 | NO | NO |
CVE-2017-2817HIGH A stack buffer overflow vulnerability exists in the ISO parsing functionality of Power Software Ltd PowerISO 6.8. A specially crafted ISO file can cause a vulnerability resulting i | May 24, 2017 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Poweriso.
Media articles that mention a CVE ID that affects a product developed by Poweriso — matched by CVE ID, not by vendor name.