Lucene search

K

Irfanview Security Vulnerabilities

cve
cve

CVE-1999-1112

Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.

8AI Score

0.017EPSS

2001-09-12 04:00 AM
22
cve
cve

CVE-2006-4231

IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.

6.8AI Score

0.006EPSS

2006-08-18 08:04 PM
25
cve
cve

CVE-2006-4374

IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.

7.1AI Score

0.002EPSS

2006-08-26 09:04 PM
19
cve
cve

CVE-2007-1245

IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.

6.6AI Score

0.008EPSS

2007-03-03 07:19 PM
32
cve
cve

CVE-2007-1867

Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.

7.8AI Score

0.103EPSS

2007-04-04 04:19 PM
26
cve
cve

CVE-2007-1948

Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.

7.7AI Score

0.005EPSS

2007-04-11 01:19 AM
25
4
cve
cve

CVE-2007-2363

Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.

7.8AI Score

0.05EPSS

2007-04-30 10:19 PM
21
cve
cve

CVE-2007-4343

Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.

7.9AI Score

0.071EPSS

2007-10-16 11:17 PM
21
cve
cve

CVE-2008-0493

fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.

7.7AI Score

0.134EPSS

2008-01-30 10:00 PM
20
cve
cve

CVE-2009-2118

Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.

8.2AI Score

0.032EPSS

2009-06-18 09:30 PM
26
cve
cve

CVE-2010-1509

IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, rela...

8.3AI Score

0.131EPSS

2010-05-14 07:30 PM
22
cve
cve

CVE-2010-1510

Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.

8.4AI Score

0.131EPSS

2010-05-14 07:30 PM
21
cve
cve

CVE-2011-5233

Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

8.3AI Score

0.104EPSS

2012-10-25 05:55 PM
22
cve
cve

CVE-2012-0897

Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

7.9AI Score

0.945EPSS

2012-01-20 05:55 PM
114
cve
cve

CVE-2012-5904

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

8.3AI Score

0.062EPSS

2012-11-17 09:55 PM
17
cve
cve

CVE-2013-5351

Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.

8.3AI Score

0.171EPSS

2014-02-14 07:55 PM
22
cve
cve

CVE-2013-6932

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.

7.9AI Score

0.047EPSS

2013-12-28 04:53 AM
29
cve
cve

CVE-2017-10729

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."

7.8CVSS

7.9AI Score

0.001EPSS

2017-07-05 08:29 PM
35
cve
cve

CVE-2017-10730

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d96."

7.8CVSS

7.9AI Score

0.001EPSS

2017-07-05 08:29 PM
29
cve
cve

CVE-2017-10731

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d80."

7.8CVSS

7.9AI Score

0.001EPSS

2017-07-05 08:29 PM
39
cve
cve

CVE-2017-10732

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."

7.8CVSS

8AI Score

0.001EPSS

2017-07-05 08:29 PM
31
cve
cve

CVE-2017-10733

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."

7.8CVSS

8AI Score

0.001EPSS

2017-07-05 08:29 PM
30
cve
cve

CVE-2017-10734

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

7.8CVSS

8AI Score

0.001EPSS

2017-07-05 08:29 PM
35
cve
cve

CVE-2017-10735

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."

7.8CVSS

8AI Score

0.001EPSS

2017-07-05 08:29 PM
28
cve
cve

CVE-2017-10924

IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529."

7.8CVSS

7.9AI Score

0.001EPSS

2017-07-05 08:29 PM
27
cve
cve

CVE-2017-10925

IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePr...

7.8CVSS

8AI Score

0.001EPSS

2017-07-05 08:29 PM
30
cve
cve

CVE-2017-10926

IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

7.8CVSS

8AI Score

0.001EPSS

2017-07-05 08:29 PM
29
cve
cve

CVE-2017-14539

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767."

7.8CVSS

8AI Score

0.0004EPSS

2017-09-18 05:29 PM
30
cve
cve

CVE-2017-14540

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x000000000001f23e."

7.8CVSS

8AI Score

0.0004EPSS

2017-09-18 05:29 PM
33
cve
cve

CVE-2017-14578

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ani file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77130000!RtlpCoalesceFreeBlocks+0x00000000000004b4."

7.8CVSS

8AI Score

0.0004EPSS

2017-09-18 05:29 PM
30
cve
cve

CVE-2017-14693

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613."

7.8CVSS

8AI Score

0.0004EPSS

2017-09-22 08:29 AM
26
cve
cve

CVE-2017-15239

IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000040db4."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
26
cve
cve

CVE-2017-15240

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132cef."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
21
cve
cve

CVE-2017-15241

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000000929f5."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
29
cve
cve

CVE-2017-15242

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x0000000000031abe."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
28
cve
cve

CVE-2017-15243

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x00000000000568a4."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
28
cve
cve

CVE-2017-15244

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

7.8CVSS

8.1AI Score

0.001EPSS

2017-10-11 06:29 PM
28
cve
cve

CVE-2017-15245

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlGetGlobalState+0x0000000000057b76."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
23
cve
cve

CVE-2017-15246

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x000000000001515b."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
27
cve
cve

CVE-2017-15247

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000001168a1."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
29
cve
cve

CVE-2017-15248

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x0000000000063ca6."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
29
cve
cve

CVE-2017-15249

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x00000000000668d6."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
35
cve
cve

CVE-2017-15250

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132e19."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
25
cve
cve

CVE-2017-15251

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x00000000000e7326."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
33
cve
cve

CVE-2017-15252

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x00000000000158cb."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
33
cve
cve

CVE-2017-15253

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x000000000007dff2."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
26
cve
cve

CVE-2017-15254

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlGetGlobalState+0x000000000007dfa5."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
29
cve
cve

CVE-2017-15256

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x0000000000019fc8."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
23
cve
cve

CVE-2017-15257

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x000000000009174a."

7.8CVSS

7.9AI Score

0.001EPSS

2017-10-11 06:29 PM
23
cve
cve

CVE-2017-15258

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000161a9c."

7.8CVSS

8AI Score

0.001EPSS

2017-10-11 06:29 PM
31
Total number of security vulnerabilities186