Lucene search

K
cve[email protected]CVE-2013-3938
HistoryMar 18, 2014 - 5:02 p.m.

CVE-2013-3938

2014-03-1817:02:52
CWE-189
web.nvd.nist.gov
20
cve-2013-3938
integer overflow
xnview
remote code execution
jxr file
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.6%

Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow.

Affected configurations

NVD
Node
xnviewxnviewMatch2.13
CPENameOperatorVersion
xnview:xnviewxnvieweq2.13

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.6%

Related for CVE-2013-3938