Vulnerabilities > Irfanview

DATE CVE VULNERABILITY TITLE RISK
2017-07-05 CVE-2017-8766 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) allows remote attackers to execute code via a crafted .mov file, because of a "User Mode Write AV near NULL" issue.
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-8370 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview FPX and Irfanview
IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different vulnerability than CVE-2017-7721.
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-8369 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10926 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview FPX and Irfanview
IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10925 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview FPX and Irfanview
IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b3ae."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10924 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview FPX and Irfanview
IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10735 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10734 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x000000000000001d."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10733 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-10732 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."
local
low complexity
irfanview CWE-119
7.8