Vulnerabilities > Irfanview

DATE CVE VULNERABILITY TITLE RISK
2021-09-28 CVE-2021-29365 Infinite Loop vulnerability in Irfanview 4.57
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component.
local
low complexity
irfanview CWE-835
5.5
2021-09-28 CVE-2021-29366 Out-of-bounds Write vulnerability in Irfanview 4.57
A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.
local
low complexity
irfanview CWE-787
7.8
2021-09-28 CVE-2021-29367 Out-of-bounds Write vulnerability in Irfanview 4.57
A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file.
local
low complexity
irfanview CWE-787
7.8
2021-02-17 CVE-2021-27362 Out-of-bounds Read vulnerability in Irfanview WPG
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to execute arbitrary code.
network
low complexity
irfanview CWE-125
critical
9.8
2021-02-17 CVE-2021-27224 Out-of-bounds Write vulnerability in Irfanview WPG
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.
network
low complexity
irfanview CWE-787
7.5
2020-12-16 CVE-2020-35133 Unrestricted Upload of File with Dangerous Type vulnerability in Irfanview 4.56
irfanView 4.56 contains an error processing parsing files of type .pcx.
network
low complexity
irfanview CWE-434
7.5
2020-06-10 CVE-2020-13906 Unspecified vulnerability in Irfanview 4.54
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7.
local
low complexity
irfanview
7.8
2020-06-10 CVE-2020-13905 Unspecified vulnerability in Irfanview 4.54
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4.
network
low complexity
irfanview
8.8
2020-01-27 CVE-2013-3486 Integer Overflow or Wraparound vulnerability in Irfanview Flashpix Plugin 4.3.4.0
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability
network
low complexity
irfanview CWE-190
critical
9.6
2019-10-08 CVE-2019-17258 Out-of-bounds Write vulnerability in Irfanview 4.53
IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000000839c.
local
low complexity
irfanview CWE-787
7.8