Xunlei develops download and media acceleration software with products including Web Thunder and Thunder that operate as client-side utilities for enhanced content delivery. The vendor's observed vulnerability exposure centers on memory-safety and code-injection weaknesses characteristic of client applications handling untrusted network data and user input. Current CVE counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xunlei over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5064MEDIUM Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in DapPlayer_Now.dll, allows remote attackers to execute arbitr | Sep 24, 2007 | 6.8 | 27 | NO | YES |
CVE-2012-2224HIGH Xunlei Thunder before 7.2.6 allows remote attackers to execute arbitrary code via a crafted file, related to a "DLL injection vulnerability." | Apr 11, 2012 | 7.5 | 23 | NO | NO |
CVE-2007-3296HIGH The ThunderServer.webThunder.1 ActiveX control in xunlei Web Thunderbolt 1.7.3.109 allows remote attackers to download arbitrary files and conduct other unauthorized actions by inv | Jun 20, 2007 | 9.3 | 23 | NO | NO |
CVE-2007-6144MEDIUM Heap-based buffer overflow in the PPlayer.XPPlayer.1 ActiveX control in pplayer.dll_1_work in Xunlei Thunder 5.7.4.401 allows remote attackers to execute arbitrary code via a long | Nov 27, 2007 | 6.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xunlei.
Media articles that mention a CVE ID that affects a product developed by Xunlei — matched by CVE ID, not by vendor name.