Vulnerabilities > Irfanview > Irfanview > 3.98

DATE CVE VULNERABILITY TITLE RISK
2014-02-14 CVE-2013-5351 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.
network
low complexity
irfanview CWE-119
7.5
2013-12-28 CVE-2013-6932 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.
network
high complexity
irfanview CWE-119
7.6
2012-11-17 CVE-2012-5904 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.
network
irfanview CWE-119
6.8
2012-10-25 CVE-2011-5233 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
network
irfanview CWE-119
4.3
2012-01-20 CVE-2012-0897 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
network
irfanview CWE-119
6.8
2010-05-14 CVE-2010-1510 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.
network
low complexity
irfanview CWE-119
5.0
2010-05-14 CVE-2010-1509 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."
network
low complexity
irfanview CWE-119
5.0
2007-04-30 CVE-2007-2363 Remote Buffer Overflow vulnerability in IrfanView .IFF Format Handling
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
network
irfanview
8.5
2006-08-26 CVE-2006-4374 Denial Of Service vulnerability in Irfanview 3.98
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.
network
high complexity
irfanview
2.6
2006-08-18 CVE-2006-4231 Denial-Of-Service vulnerability in Irfanview 3.98
IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.
network
high complexity
irfanview
2.6