Visionsoft's vulnerability profile centers on audit software, where disclosed issues reflect challenges in cryptographic implementation and integrity verification. The recurring weakness classes—cryptographic algorithm risks and validation gaps—are typical for audit and compliance-focused tooling that handles sensitive data or policy enforcement. Current exposure counts, severity assessment, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Visionsoft over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4148HIGH Heap-based buffer overflow in the Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote attackers to cause a denial of service (persistent daemon cr | Aug 3, 2007 | 10.0 | 26 | NO | NO |
CVE-2007-4149HIGH The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 does not require authentication for (1) the "LOG." command, which allows remote attackers to create or o | Aug 3, 2007 | 10.0 | 26 | NO | NO |
CVE-2007-4152HIGH The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote attackers to conduct replay attacks by capturing and resending data from the DETAILS and P | Aug 3, 2007 | 9.3 | 23 | NO | NO |
CVE-2007-4150HIGH The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote attackers to obtain se | Aug 3, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-4151MEDIUM The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 allows remote attackers to obtain sensitive information via (1) a LOG.ON command, which reveals the logg | Aug 3, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Visionsoft.
Media articles that mention a CVE ID that affects a product developed by Visionsoft — matched by CVE ID, not by vendor name.