UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite values and paste it into the Output FileName field to trigger a denial of service crash.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite values and paste it into the Output FileName field to trigger a denial of service crash. | |
| Title | UltraISO 9.7.1.3519 Buffer Overflow via Output FileName | |
| First Time appeared |
Ultraiso
Ultraiso ultraiso |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:ultraiso:ultraiso:9.35:*:*:*:premium:*:*:* cpe:2.3:a:ultraiso:ultraiso:9.7.1.3519:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ultraiso
Ultraiso ultraiso |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-22T14:57:01.848Z
Reserved: 2026-04-22T14:25:46.712Z
Link: CVE-2018-25267
No data.
Status : Received
Published: 2026-04-22T16:16:47.237
Modified: 2026-04-22T16:16:47.237
Link: CVE-2018-25267
No data.
OpenCVE Enrichment
No data.
Weaknesses