Ultraedit is a text and code editor product with a niche vulnerability footprint centered on the core editor application and its 32-bit variant, where the observed weakness classes relate to untrusted search paths and configuration handling. Treat this as a compact vendor profile rather than a broad trend; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultraedit over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3402HIGH Untrusted search path vulnerability in IDM Computer Solutions UltraEdit 16.20.0.1009, 16.10.0.1036, and probably other versions allows local users, and possibly remote attackers, t | Sep 16, 2010 | 9.3 | 27 | NO | NO |
CVE-2017-12580HIGH An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affe | Mar 2, 2020 | 7.8 | 24 | NO | NO |
CVE-2001-0983MEDIUM UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges. | Aug 31, 2001 | 4.6 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultraedit.
Media articles that mention a CVE ID that affects a product developed by Ultraedit — matched by CVE ID, not by vendor name.