xnview CVE Vulnerabilities & Metrics

Focus on xnview vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About xnview Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with xnview. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total xnview CVEs: 157
Earliest CVE date: 24 Mar 2008, 18:44 UTC
Latest CVE date: 29 Dec 2023, 04:15 UTC

Latest CVE reference: CVE-2023-52174

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical xnview CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.65

Max CVSS: 9.3

Critical CVEs (≥9): 7

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 151
7.0-8.9 4
9.0-10.0 7

CVSS Distribution Chart

Top 5 Highest CVSS xnview CVEs

These are the five CVEs with the highest CVSS scores for xnview, sorted by severity first and recency.

All CVEs for xnview

CVE-2023-52174 xnview vulnerability CVSS: 0 29 Dec 2023, 04:15 UTC

XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.

CVE-2023-52173 xnview vulnerability CVSS: 0 29 Dec 2023, 04:15 UTC

XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.

CVE-2023-46587 xnview vulnerability CVSS: 0 27 Oct 2023, 23:15 UTC

Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.

CVE-2023-43251 xnview vulnerability CVSS: 0 19 Oct 2023, 15:15 UTC

XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2023-43252 xnview vulnerability CVSS: 0 19 Oct 2023, 13:15 UTC

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

CVE-2023-43250 xnview vulnerability CVSS: 0 18 Oct 2023, 16:15 UTC

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-28835 xnview vulnerability CVSS: 0 11 Aug 2023, 14:15 UTC

Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.

CVE-2021-28427 xnview vulnerability CVSS: 0 11 Aug 2023, 14:15 UTC

Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.

CVE-2020-23887 xnview vulnerability CVSS: 4.3 10 Nov 2021, 22:15 UTC

XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.

CVE-2020-23886 xnview vulnerability CVSS: 4.3 10 Nov 2021, 22:15 UTC

XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree.

CVE-2013-3493 xnview vulnerability CVSS: 7.5 27 Jan 2020, 15:15 UTC

XnView 2.03 has an integer overflow vulnerability

CVE-2013-3492 xnview vulnerability CVSS: 7.5 27 Jan 2020, 15:15 UTC

XnView 2.03 has a stack-based buffer overflow vulnerability

CVE-2013-3941 xnview vulnerability CVSS: 7.5 02 Jan 2020, 20:15 UTC

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.

CVE-2013-3939 xnview vulnerability CVSS: 6.8 02 Jan 2020, 20:15 UTC

xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.

CVE-2013-3937 xnview vulnerability CVSS: 6.8 02 Jan 2020, 20:15 UTC

Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.

CVE-2013-3247 xnview vulnerability CVSS: 6.8 02 Jan 2020, 20:15 UTC

Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.

CVE-2013-3246 xnview vulnerability CVSS: 6.8 02 Jan 2020, 20:15 UTC

Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.

CVE-2019-17262 xnview vulnerability CVSS: 4.6 08 Oct 2019, 12:15 UTC

XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.

CVE-2019-17261 xnview vulnerability CVSS: 4.6 08 Oct 2019, 12:15 UTC

XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.

CVE-2019-13262 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.

CVE-2019-13261 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.

CVE-2019-13260 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07.

CVE-2019-13259 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e566.

CVE-2019-13258 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.

CVE-2019-13257 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.

CVE-2019-13256 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e849.

CVE-2019-13255 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.

CVE-2019-13254 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.

CVE-2019-13253 xnview vulnerability CVSS: 6.8 04 Jul 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.

CVE-2019-13085 xnview vulnerability CVSS: 6.8 30 Jun 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.

CVE-2019-13084 xnview vulnerability CVSS: 6.8 30 Jun 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739.

CVE-2019-13083 xnview vulnerability CVSS: 6.8 30 Jun 2019, 16:15 UTC

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.

CVE-2019-9969 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.

CVE-2019-9968 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem.

CVE-2019-9967 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.

CVE-2019-9966 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.

CVE-2019-9965 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap.

CVE-2019-9964 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlpNtMakeTemporaryKey.

CVE-2019-9963 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap.

CVE-2019-9962 xnview vulnerability CVSS: 6.8 24 Mar 2019, 02:29 UTC

XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy.

CVE-2018-15176 xnview vulnerability CVSS: 6.8 08 Aug 2018, 00:29 UTC

XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file.

CVE-2018-15175 xnview vulnerability CVSS: 6.8 08 Aug 2018, 00:29 UTC

XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file.

CVE-2018-15174 xnview vulnerability CVSS: 6.8 08 Aug 2018, 00:29 UTC

XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO file.

CVE-2017-15789 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000048e7."

CVE-2017-15788 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x0000000000002d83."

CVE-2017-15787 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063."

CVE-2017-15786 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x00000000001a78db."

CVE-2017-15785 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation near NULL starting at Unknown Symbol @ 0x0000000000000000 called from CADImage+0x0000000000286a79."

CVE-2017-15784 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to an "Illegal Instruction Violation starting at xnview+0x0000000000370074."

CVE-2017-15783 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285ce1."

CVE-2017-15782 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000032eb."

CVE-2017-15781 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Read Access Violation on Control Flow starting at CADImage+0x0000000000286a76."

CVE-2017-15780 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285dad."

CVE-2017-15779 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at CADImage+0x00000000000034b0."

CVE-2017-15778 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285de7."

CVE-2017-15777 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at CADImage+0x0000000000288750."

CVE-2017-15776 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285ec1."

CVE-2017-15775 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000259aa4."

CVE-2017-15774 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls Code Flow starting at CADImage+0x0000000000221a9a."

CVE-2017-15773 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285d79."

CVE-2017-15772 xnview vulnerability CVSS: 6.8 22 Oct 2017, 20:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285e9d."

CVE-2017-15803 xnview vulnerability CVSS: 6.8 22 Oct 2017, 19:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000150."

CVE-2017-15802 xnview vulnerability CVSS: 6.8 22 Oct 2017, 19:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000087."

CVE-2017-15801 xnview vulnerability CVSS: 6.8 22 Oct 2017, 19:29 UTC

XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResSearchResourceInsideDirectory+0x000000000000029e."

CVE-2017-14580 xnview vulnerability CVSS: 4.6 18 Sep 2017, 17:29 UTC

XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000870f."

CVE-2017-14541 xnview vulnerability CVSS: 4.6 18 Sep 2017, 17:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x000000000001f23e."

CVE-2017-14538 xnview vulnerability CVSS: 4.6 18 Sep 2017, 17:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008823."

CVE-2017-14285 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlInterlockedPopEntrySList+0x000000000000039b."

CVE-2017-14284 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlGetCurrentDirectory_U+0x000000000000016c."

CVE-2017-14283 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000008fe4."

CVE-2017-14282 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005862."

CVE-2017-14281 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at jbig2dec+0x00000000000090f1."

CVE-2017-14280 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at jbig2dec+0x000000000000571d."

CVE-2017-14279 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005643."

CVE-2017-14278 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005940."

CVE-2017-14277 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005956."

CVE-2017-14276 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Possible Stack Corruption starting at jbig2dec+0x0000000000002fbe."

CVE-2017-14275 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVE-2017-14274 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008706."

CVE-2017-14273 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlInterlockedPopEntrySList+0x00000000000003b0."

CVE-2017-14272 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000595d."

CVE-2017-14271 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlImpersonateSelfEx+0x000000000000024e."

CVE-2017-14270 xnview vulnerability CVSS: 4.6 11 Sep 2017, 18:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlFillMemoryUlong+0x0000000000000010."

CVE-2017-9914 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .bie file, related to a "Read Access Violation on Block Data Move starting at Xjbig+0x000000000000121b."

CVE-2017-9913 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!TpAllocCleanupGroup+0x00000000000003d7."

CVE-2017-9912 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."

CVE-2017-9911 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at Xfpx+0x0000000000010e81."

CVE-2017-9910 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to an "Error Code (0xc000041d) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVE-2017-9909 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlAddAccessAllowedAce+0x000000000000027a."

CVE-2017-9908 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at Xfpx+0x000000000000d6da."

CVE-2017-9907 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Possible Stack Corruption starting at Xfpx!gffGetFormatInfo+0x0000000000022e1f."

CVE-2017-9906 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at Xfpx!gffGetFormatInfo+0x0000000000028508."

CVE-2017-9905 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at Xfpx!gffGetFormatInfo+0x00000000000228e8."

CVE-2017-9904 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."

CVE-2017-9903 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx+0x00000000000117ff."

CVE-2017-9902 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x0000000000020e91."

CVE-2017-9901 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls subsequent Write Address starting at Xfpx!gffGetFormatInfo+0x000000000002bfd5."

CVE-2017-9900 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e385."

CVE-2017-9899 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e388."

CVE-2017-9898 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004cbb."

CVE-2017-9897 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x000000000000dcab."

CVE-2017-9896 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000013e8a."

CVE-2017-9895 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000020e95."

CVE-2017-9894 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000029272."

CVE-2017-9893 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000012548."

CVE-2017-9529 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004efd."

CVE-2017-8781 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted JPEG 2000 file that is mishandled during the opening of a directory in "Browser" mode, because of a "Stack Buffer Overrun" issue.

CVE-2017-8381 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled during the opening of a directory in "Browser" mode, because of a "User Mode Write AV near NULL" in XnView.exe.

CVE-2017-8282 xnview vulnerability CVSS: 6.8 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mov file that is mishandled during the opening of a directory in "Browser" mode, because of a "User Mode Write AV near NULL" in XnView.exe.

CVE-2017-10783 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."

CVE-2017-10782 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."

CVE-2017-10781 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByName+0x00000000000000a5."

CVE-2017-10780 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000372b4a."

CVE-2017-10779 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20."

CVE-2017-10778 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000233125."

CVE-2017-10777 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000372b24."

CVE-2017-10776 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to a "Read Access Violation starting at ntdll_77df0000!LdrShutdownProcess+0x0000000000000130."

CVE-2017-10775 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to a "Read Access Violation starting at GDI32!ScriptGetCMapWithSurrogate+0x00000000000001cb."

CVE-2017-10774 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!FindSortHashNode+0x0000000000000040."

CVE-2017-10773 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at MSCTF!_CtfImeCreateThreadMgr+0x00000000000000a8."

CVE-2017-10772 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!memcmp+0x0000000000000018" (with RPC initialization).

CVE-2017-10771 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCreateSplitBlock+0x0000000000000510."

CVE-2017-10770 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCreateSplitBlock+0x000000000000053a."

CVE-2017-10769 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!memcmp+0x0000000000000018" (without RPC initialization).

CVE-2017-10768 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpInsertFreeBlock+0x00000000000001ca."

CVE-2017-10767 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!StateObjectListFind+0x0000000000000005."

CVE-2017-10766 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at GDI32!ScriptStringAnalyse+0x00000000000001c8."

CVE-2017-10765 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."

CVE-2017-10764 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at COMCTL32!Tab_OnGetItem+0x000000000000002f."

CVE-2017-10763 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByHandle+0x0000000000000031."

CVE-2017-10762 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x000000000000042f."

CVE-2017-10761 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."

CVE-2017-10760 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at COMCTL32!SetStatusText+0x0000000000000029."

CVE-2017-10759 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpInsertDependencyRecord+0x0000000000000039."

CVE-2017-10758 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000004b4."

CVE-2017-10757 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000001b6."

CVE-2017-10756 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpRemoveUCRBlock+0x0000000000000046."

CVE-2017-10755 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpInitializeThread+0x000000000000010b."

CVE-2017-10754 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."

CVE-2017-10753 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByMapping+0x0000000000000046."

CVE-2017-10752 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."

CVE-2017-10751 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at GDI32!GenericEngineGetGlyphs+0x0000000000000133."

CVE-2017-10750 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."

CVE-2017-10749 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVE-2017-10748 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."

CVE-2017-10747 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa."

CVE-2017-10746 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."

CVE-2017-10745 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!RtlProcessFlsData+0x00000000000000b0."

CVE-2017-10744 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Read Access Violation on Control Flow starting at COMCTL32!CToolTipsMgr::s_ToolTipsWndProc+0x0000000000000032."

CVE-2017-10743 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!LdrpInitializeNode+0x000000000000015b."

CVE-2017-10742 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x00000000380a0500 called from ntdll_77df0000!LdrxCallInitRoutine+0x0000000000000016."

CVE-2017-10741 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."

CVE-2017-10740 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlRbInsertNodeEx+0x000000000000002d."

CVE-2017-10739 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000000c1b541c called from xnview+0x00000000003826ec."

CVE-2017-10738 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000002f32332f called from KERNELBASE!CompareStringW+0x0000000000000082."

CVE-2017-10737 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000002e6."

CVE-2017-10736 xnview vulnerability CVSS: 4.6 05 Jul 2017, 20:29 UTC

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at msvcrt!_VEC_memzero+0x000000000000006a."

CVE-2012-4988 xnview vulnerability CVSS: 9.3 09 Jul 2014, 14:55 UTC

Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

CVE-2013-3938 xnview vulnerability CVSS: 9.3 18 Mar 2014, 17:02 UTC

Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow.

CVE-2013-2577 xnview vulnerability CVSS: 9.3 09 Aug 2013, 21:55 UTC

Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.

CVE-2012-0282 xnview vulnerability CVSS: 6.8 17 Jul 2012, 21:55 UTC

Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image.

CVE-2012-0277 xnview vulnerability CVSS: 6.8 17 Jul 2012, 21:55 UTC

Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT image.

CVE-2012-0276 xnview vulnerability CVSS: 6.8 17 Jul 2012, 21:55 UTC

Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.

CVE-2012-0685 xnview vulnerability CVSS: 9.3 09 May 2012, 10:33 UTC

Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684.

CVE-2012-0684 xnview vulnerability CVSS: 9.3 09 May 2012, 10:33 UTC

Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685.

CVE-2012-1051 xnview vulnerability CVSS: 6.8 13 Feb 2012, 19:55 UTC

Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

CVE-2011-1338 xnview vulnerability CVSS: 6.9 11 Jul 2011, 20:55 UTC

Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item.

CVE-2010-1932 xnview vulnerability CVSS: 9.3 16 Jun 2010, 20:30 UTC

Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that contains a malformed Encoding field.

CVE-2009-4001 xnview vulnerability CVSS: 9.3 15 Mar 2010, 13:28 UTC

Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.

CVE-2008-1461 xnview vulnerability CVSS: 7.6 24 Mar 2008, 18:44 UTC

Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.