CVE-2013-5351
- EPSS 5.52%
- Veröffentlicht 14.02.2014 19:55:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.
CVE-2013-6932
- EPSS 9.88%
- Veröffentlicht 28.12.2013 04:53:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumb...
CVE-2012-5904
- EPSS 4.07%
- Veröffentlicht 17.11.2012 21:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.
CVE-2011-5233
- EPSS 48.55%
- Veröffentlicht 25.10.2012 17:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
CVE-2012-0897
- EPSS 67.09%
- Veröffentlicht 20.01.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
- EPSS 3.68%
- Veröffentlicht 14.05.2010 19:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file...
- EPSS 4.77%
- Veröffentlicht 14.05.2010 19:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.
CVE-2009-2118
- EPSS 2.8%
- Veröffentlicht 18.06.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
CVE-2008-0493
- EPSS 7.61%
- Veröffentlicht 30.01.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.
CVE-2007-4343
- EPSS 4.67%
- Veröffentlicht 16.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.