Vulnerabilities > Irfanview

DATE CVE VULNERABILITY TITLE RISK
2010-05-14 CVE-2010-1509 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."
network
low complexity
irfanview CWE-119
5.0
2009-06-18 CVE-2009-2118 Code Injection vulnerability in Irfanview 4.23
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
network
irfanview CWE-94
6.8
2009-04-09 CVE-2009-0197 Numeric Errors vulnerability in Irfanview Formats 4.00/4.10/4.20
Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.
network
irfanview CWE-189
critical
9.3
2008-01-30 CVE-2008-0493 Buffer Errors vulnerability in Irfanview 4.10
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption.
network
irfanview CWE-119
critical
9.3
2007-10-16 CVE-2007-4343 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Irfanview 3.99/4.00
Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.
network
high complexity
irfanview CWE-119
5.1
2007-04-30 CVE-2007-2363 Remote Buffer Overflow vulnerability in IrfanView .IFF Format Handling
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
network
irfanview
8.5
2007-04-11 CVE-2007-1948 Denial-Of-Service vulnerability in Irfanview 3.99
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.
network
irfanview
critical
9.3
2007-04-04 CVE-2007-1867 Remote Buffer Overflow vulnerability in Irfanview 3.99
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
network
low complexity
irfanview
critical
10.0
2007-03-03 CVE-2007-1245 Buffer Errors vulnerability in Irfanview 3.99
IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.
network
irfanview CWE-119
4.3
2006-08-26 CVE-2006-4374 Denial Of Service vulnerability in Irfanview 3.98
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.
network
high complexity
irfanview
2.6