Vulnerabilities (CVE)

Filtered by vendor Xnview
Filtered by product Xnview
Angry Yack Logo
Total 156 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-0282 1 Xnview 1 Xnview 2025-04-11 6.8 MEDIUM N/A
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image.
CVE-2012-1051 1 Xnview 1 Xnview 2025-04-11 6.8 MEDIUM N/A
Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
CVE-2012-0276 1 Xnview 1 Xnview 2025-04-11 6.8 MEDIUM N/A
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.
CVE-2012-0277 1 Xnview 1 Xnview 2025-04-11 6.8 MEDIUM N/A
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT image.
CVE-2011-1338 1 Xnview 1 Xnview 2025-04-11 6.9 MEDIUM N/A
Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item.
CVE-2012-0685 1 Xnview 1 Xnview 2025-04-11 9.3 HIGH N/A
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684.
CVE-2013-2577 1 Xnview 1 Xnview 2025-04-11 9.3 HIGH N/A
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
CVE-2008-1461 1 Xnview 1 Xnview 2025-04-09 7.6 HIGH N/A
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.
CVE-2023-46587 1 Xnview 1 Xnview 2024-11-21 N/A 7.8 HIGH
Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.
CVE-2021-28835 1 Xnview 1 Xnview 2024-11-21 N/A 7.8 HIGH
Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.
CVE-2021-28427 1 Xnview 1 Xnview 2024-11-21 N/A 7.8 HIGH
Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.
CVE-2019-17262 1 Xnview 1 Xnview 2024-11-21 4.6 MEDIUM 7.8 HIGH
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.
CVE-2019-17261 1 Xnview 1 Xnview 2024-11-21 4.6 MEDIUM 7.8 HIGH
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.
CVE-2019-13262 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.
CVE-2019-13261 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.
CVE-2019-13260 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07.
CVE-2019-13259 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e566.
CVE-2019-13258 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.
CVE-2019-13257 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.
CVE-2019-13256 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e849.
CVE-2019-13255 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.
CVE-2019-13254 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.
CVE-2019-13253 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.
CVE-2019-13085 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.
CVE-2019-13084 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739.
CVE-2019-13083 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.
CVE-2018-15176 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file.
CVE-2018-15175 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file.
CVE-2018-15174 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO file.
CVE-2013-3941 1 Xnview 1 Xnview 2024-11-21 7.5 HIGH 9.8 CRITICAL
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.
CVE-2013-3939 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.
CVE-2013-3937 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.
CVE-2013-3493 1 Xnview 1 Xnview 2024-11-21 7.5 HIGH 9.8 CRITICAL
XnView 2.03 has an integer overflow vulnerability
CVE-2013-3492 1 Xnview 1 Xnview 2024-11-21 7.5 HIGH 9.8 CRITICAL
XnView 2.03 has a stack-based buffer overflow vulnerability
CVE-2013-3247 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
CVE-2013-3246 1 Xnview 1 Xnview 2024-11-21 6.8 MEDIUM 7.8 HIGH
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.