Roxio develops a range of multimedia authoring and playback applications—including Toast, CinePlayer, and Easy Media Creator—that process and manipulate media files, presenting an attack surface centered on parsing and codec handling. Its vulnerability profile centers on buffer-boundary violations and race conditions inherent to media processing codebases, and vulnerabilities affecting the vendor frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roxio over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0348HIGH Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other prod | Mar 21, 2007 | 9.3 | 61 | NO | YES |
CVE-2007-1559HIGH Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to | Apr 11, 2007 | 9.3 | 59 | NO | YES |
CVE-2008-4384HIGH Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code | Oct 7, 2008 | 9.3 | 57 | NO | YES |
CVE-2009-4841HIGH Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argu | May 6, 2010 | 9.3 | 38 | NO | YES |
CVE-2009-4840HIGH Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the Se | May 6, 2010 | 9.3 | 36 | NO | YES |
CVE-2010-5236MEDIUM Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a Trojan horse homeutils9.dll file in the current working dir | Sep 7, 2012 | 6.9 | 30 | NO | YES |
CVE-2010-5195MEDIUM Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9.dll file in the current working directory, as demonstrated | Sep 6, 2012 | 6.9 | 29 | NO | YES |
CVE-2007-3829HIGH Multiple stack-based buffer overflows in (a) InterActual Player 2.60.12.0717 and (b) Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via a (1) long FailURL at | Jul 17, 2007 | 9.3 | 28 | NO | NO |
CVE-2009-1566HIGH Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions | Dec 3, 2009 | 9.3 | 27 | NO | NO |
CVE-2004-1398MEDIUM Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitr | Dec 31, 2004 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roxio.
Media articles that mention a CVE ID that affects a product developed by Roxio — matched by CVE ID, not by vendor name.