faststone CVE Vulnerabilities & Metrics

Focus on faststone vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About faststone Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with faststone. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total faststone CVEs: 30
Earliest CVE date: 29 Mar 2005, 05:00 UTC
Latest CVE date: 22 Nov 2024, 22:15 UTC

Latest CVE reference: CVE-2024-9114

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical faststone CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.41

Max CVSS: 9.3

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 29
7.0-8.9 0
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS faststone CVEs

These are the five CVEs with the highest CVSS scores for faststone, sorted by severity first and recency.

All CVEs for faststone

CVE-2024-9114 faststone vulnerability CVSS: 0 22 Nov 2024, 22:15 UTC

FastStone Image Viewer GIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of GIF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25145.

CVE-2024-9113 faststone vulnerability CVSS: 0 22 Nov 2024, 22:15 UTC

FastStone Image Viewer TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TGA files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25140.

CVE-2024-9112 faststone vulnerability CVSS: 0 22 Nov 2024, 22:15 UTC

FastStone Image Viewer PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FastStone Image Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25102.

CVE-2022-36947 faststone vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.

CVE-2021-26237 faststone vulnerability CVSS: 6.8 18 Mar 2021, 14:15 UTC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-26235 faststone vulnerability CVSS: 6.8 18 Mar 2021, 14:15 UTC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-26234 faststone vulnerability CVSS: 6.8 18 Mar 2021, 14:15 UTC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-26233 faststone vulnerability CVSS: 6.8 18 Mar 2021, 14:15 UTC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-26236 faststone vulnerability CVSS: 6.8 18 Mar 2021, 13:15 UTC

FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code execution when a user opens or views a malformed/specially crafted CUR file.

CVE-2020-35845 faststone vulnerability CVSS: 6.8 26 Jan 2021, 18:15 UTC

FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x96cf.

CVE-2020-35844 faststone vulnerability CVSS: 6.8 26 Jan 2021, 18:15 UTC

FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0xbe9c4.

CVE-2020-35843 faststone vulnerability CVSS: 4.3 26 Jan 2021, 18:15 UTC

FastStone Image Viewer 7.5 has an out-of-bounds write (via a crafted image file) at FSViewer.exe+0x956e.

CVE-2019-13246 faststone vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a9601.

CVE-2019-13245 faststone vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a95b1.

CVE-2019-13244 faststone vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x0000000000002d7d.

CVE-2018-15817 faststone vulnerability CVSS: 4.3 26 Mar 2019, 20:29 UTC

FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.

CVE-2018-15816 faststone vulnerability CVSS: 4.3 26 Mar 2019, 20:29 UTC

FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d via a crafted image file.

CVE-2018-15815 faststone vulnerability CVSS: 4.3 26 Mar 2019, 20:29 UTC

FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a via a crafted image file.

CVE-2018-15814 faststone vulnerability CVSS: 4.3 26 Mar 2019, 20:29 UTC

FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.

CVE-2018-15813 faststone vulnerability CVSS: 4.3 26 Mar 2019, 20:29 UTC

FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image file.

CVE-2018-11707 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Read and Execute AV at 0x0057898e, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2018-11706 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578dd8, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2018-11705 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cc4, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2018-11704 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d7d, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2018-11703 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d6a, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2018-11702 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cb3, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2018-11701 faststone vulnerability CVSS: 6.8 20 Jun 2018, 01:29 UTC

FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2017-8826 faststone vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

FastStone Image Viewer 6.2 has a "User Mode Write AV" issue, possibly related to the jpeg_mem_term function in jmemnobs.c in libjpeg. This issue can be triggered by a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2017-8785 faststone vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

FastStone Image Viewer 6.2 has a "Data from Faulting Address may be used as a return value" issue. This issue can be triggered by a malformed JPEG 2000 file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

CVE-2017-6078 faststone vulnerability CVSS: 4.3 21 Feb 2017, 07:59 UTC

FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.

CVE-2008-5870 faststone vulnerability CVSS: 4.3 08 Jan 2009, 18:30 UTC

FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with large width and height values, possibly a related issue to CVE-2007-1942.

CVE-2007-1942 faststone vulnerability CVSS: 9.3 11 Apr 2007, 01:19 UTC

Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.

CVE-2007-1764 faststone vulnerability CVSS: 6.0 30 Mar 2007, 00:19 UTC

Stack-based buffer overflow in FastStone Image Viewer 2.8 allows user-assisted remote attackers to execute arbitrary code via a crafted JPG image.

CVE-2005-0950 faststone vulnerability CVSS: 5.0 29 Mar 2005, 05:00 UTC

Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.