acdsee CVE Vulnerabilities & Metrics

Focus on acdsee vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About acdsee Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with acdsee. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total acdsee CVEs: 11
Earliest CVE date: 15 Nov 2007, 22:46 UTC
Latest CVE date: 26 Jan 2021, 18:16 UTC

Latest CVE reference: CVE-2021-26026

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical acdsee CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 7.27

Max CVSS: 10.0

Critical CVEs (≥9): 4

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 14
7.0-8.9 1
9.0-10.0 4

CVSS Distribution Chart

Top 5 Highest CVSS acdsee CVEs

These are the five CVEs with the highest CVSS scores for acdsee, sorted by severity first and recency.

All CVEs for acdsee

CVE-2021-26026 acdsee vulnerability CVSS: 6.8 26 Jan 2021, 18:16 UTC

PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.

CVE-2021-26025 acdsee vulnerability CVSS: 6.8 26 Jan 2021, 18:16 UTC

PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.

CVE-2020-29595 acdsee vulnerability CVSS: 7.5 07 Dec 2020, 19:15 UTC

PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000031aa.

CVE-2019-15293 acdsee vulnerability CVSS: 4.6 21 Aug 2019, 06:15 UTC

An issue was discovered in ACDSee Photo Studio Standard 22.1 Build 1159. There is a User Mode Write AV starting at IDE_ACDStd!IEP_ShowPlugInDialog+0x000000000023d060.

CVE-2019-13252 acdsee vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000001172b0.

CVE-2019-13251 acdsee vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000c47ff.

CVE-2019-13250 acdsee vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9c2f.

CVE-2019-13249 acdsee vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9e7a.

CVE-2019-13248 acdsee vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x0000000000002450.

CVE-2019-13247 acdsee vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000024ed.

CVE-2017-2886 acdsee vulnerability CVSS: 6.8 11 Dec 2017, 22:29 UTC

A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in potential code execution. An attacker can send a specific .PSD file to trigger this vulnerability.

CVE-2011-5153 acdsee vulnerability CVSS: 6.3 06 Sep 2012, 10:41 UTC

Untrusted search path vulnerability in FotoSlate 4.0 Build 146 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .plp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2011-5152 acdsee vulnerability CVSS: 6.9 06 Sep 2012, 10:41 UTC

Multiple untrusted search path vulnerabilities in ACDSee Photo Editor 2008 5.x build 291 allow local users to gain privileges via a Trojan horse (1) Wintab32.dll or (2) CV11-DialogEditor.dll file in the current working directory, as demonstrated by a directory that contains a .apd file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2011-5151 acdsee vulnerability CVSS: 6.9 06 Sep 2012, 10:41 UTC

Untrusted search path vulnerability in ACDSee Picture Frame Manager 1.0 Build 81 allows local users to gain privileges via a Trojan horse ShellIntMgrPFMU.dll file in the current working directory, as demonstrated by a directory that contains a .jpg file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2011-2595 acdsee vulnerability CVSS: 10.0 14 Sep 2011, 17:17 UTC

Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code via a long id parameter in a (1) String or (2) Int tag in a FotoSlate Project (aka PLP) file.

CVE-2008-0715 acdsee vulnerability CVSS: 9.3 12 Feb 2008, 02:00 UTC

Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file. NOTE: this might be the same as CVE-2007-6009.

CVE-2007-4344 acdsee vulnerability CVSS: 9.3 15 Nov 2007, 22:46 UTC

Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an LHA archive to the AM_LHA.apl plug-in, resulting in a heap-based buffer overflow.

CVE-2007-6009 acdsee vulnerability CVSS: 9.3 15 Nov 2007, 22:46 UTC

Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.

CVE-2007-6007 acdsee vulnerability CVSS: 6.8 15 Nov 2007, 22:46 UTC

Integer overflow in the ID_PSP.apl plug-in for ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted PSP image that triggers a heap-based buffer overflow.