Back to Database
Status published
Critical
CVE-2009-1260
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow...
Vulnerability Description
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-1260
Credits & Attribution
No credits recorded in the NVD database.
References
More from ezbsystems
View All →CVE-2010-5255
Untrusted search path vulnerability in UltraISO 9.3.6.2750 allows local users...
Medium
6.9
CVE-2008-4825
Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions...
Critical
9.3
CVE-2008-3871
Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other...
Critical
9.3
Affected Vendor
ezbsystems
View all reports →Affected Software
ultraiso
Vulnerable Versions:
0, 3.1, 3.1_sr1, 3.1_sr2, 4.0, 4.1, 4.5, 5.0, 5.1, 5.55, 5.55_sr-1, 5.55_sr-2, 6.0, 6.1, 6.5, 6.51, 6.52, 6.52_sr-1, 6.52_sr-2, 6.56_sr-1, 6.56_sr-2, 7.0, 7.1, 7.5, 7.6, 7.21_sr-1, 7.21_sr-2, 7.22_me, 7.23, 7.25, 7.51, 7.52, 7.55, 7.56, 7.62, 7.65, 7.65_sr-2, 7.66, 8, 8.2, 8.6, 8.12, 8.51, 8.61, 8.62, 8.63, 8.65, 8.66, 9.0, 9.1.2, 9.2, 9.3, 9.3.1, 9.3.2
Timeline
Official Publish:
April 7th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.