CVE-2017-2804: Corel Coreldraw Photo Paint x8

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A remote out of bound write vulnerability exists in the TIFF parsing functionality of Core PHOTO-PAINT X8 18.1.0.661. A specially crafted TIFF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific TIFF file to trigger this vulnerability.

Affected products

  • Corel Coreldraw Photo Paint x8: version 18.1.0.661 only

Published 2018-04-24. Last modified 2026-06-17.