Vulnerabilities > Irfanview > Irfanview > 3.99
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-02-14 | CVE-2013-5351 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file. | 7.5 |
2013-12-28 | CVE-2013-6932 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window. | 7.6 |
2012-11-17 | CVE-2012-5904 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image. | 6.8 |
2012-10-25 | CVE-2011-5233 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file. | 4.3 |
2012-01-20 | CVE-2012-0897 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | 6.8 |
2010-05-14 | CVE-2010-1510 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression. | 5.0 |
2010-05-14 | CVE-2010-1509 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error." | 5.0 |
2007-10-16 | CVE-2007-4343 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview 3.99/4.00 Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file. | 5.1 |
2007-04-30 | CVE-2007-2363 | Remote Buffer Overflow vulnerability in IrfanView .IFF Format Handling Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. network irfanview | 8.5 |
2007-04-11 | CVE-2007-1948 | Denial-Of-Service vulnerability in Irfanview 3.99 Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp. | 9.3 |