wibu
Security Productscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting wibu.
- CVE-2020-37017CodeMeter 6.60 - 'CodeMeter.exe' Unquoted Service Path7.8
- CVE-2021-47810WibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path7.8
- CVE-2025-47809Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation wit...8.2
- CVE-2024-45182An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resul...5.5
- CVE-2024-45181An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in ...7.8
- CVE-2023-3935Wibu: Buffer Overflow in CodeMeter Runtime9.8
- CVE-2021-41057In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.7.1
- CVE-2021-20094A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server.7.5
- CVE-2021-20093A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter...9.1
- CVE-2020-16233An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.7.5
- CVE-2020-14513CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.7.5
- CVE-2020-14515CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to buil...7.5
- CVE-2020-14519This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API stil...7.5
- CVE-2020-14517Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accep...9.8
- CVE-2020-14509Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted ...9.8