Vulnerabilities > Irfanview > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-11 CVE-2017-15240 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132cef."
network
irfanview CWE-119
6.8
2017-10-11 CVE-2017-15239 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000040db4."
network
irfanview CWE-119
6.8
2017-09-22 CVE-2017-14693 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613."
local
low complexity
irfanview CWE-119
4.6
2017-09-18 CVE-2017-14578 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ani file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77130000!RtlpCoalesceFreeBlocks+0x00000000000004b4."
local
low complexity
irfanview CWE-119
4.6
2017-09-18 CVE-2017-14540 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x000000000001f23e."
local
low complexity
irfanview CWE-119
4.6
2017-09-18 CVE-2017-14539 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767."
local
low complexity
irfanview CWE-119
4.6
2017-07-05 CVE-2017-9923 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and Tools
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!EnumResourceTypesInternal+0x0000000000000589."
4.4
2017-07-05 CVE-2017-9922 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and Tools
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpCompareResourceNames_U+0x0000000000000062."
4.4
2017-07-05 CVE-2017-9921 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and Tools
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResGetMappingSize+0x00000000000003cc."
4.4
2017-07-05 CVE-2017-9920 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and Tools
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResSearchResourceInsideDirectory+0x000000000000029e."
4.4