Vulnerabilities
Vulnerable Software
Irfanview:  >> Irfanview  Security Vulnerabilities
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."
CVSS Score
5.0
EPSS Score
0.037
Published
2010-05-14
Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.
CVSS Score
5.0
EPSS Score
0.048
Published
2010-05-14
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
CVSS Score
6.8
EPSS Score
0.028
Published
2009-06-18
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.
CVSS Score
9.3
EPSS Score
0.076
Published
2008-01-30
Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.
CVSS Score
5.1
EPSS Score
0.047
Published
2007-10-16
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
CVSS Score
8.5
EPSS Score
0.223
Published
2007-04-30
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.
CVSS Score
9.3
EPSS Score
0.06
Published
2007-04-11
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
CVSS Score
10.0
EPSS Score
0.283
Published
2007-04-04
IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.
CVSS Score
4.3
EPSS Score
0.006
Published
2007-03-03
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.
CVSS Score
2.6
EPSS Score
0.04
Published
2006-08-26


Contact Us

Shodan ® - All rights reserved