Vulnerabilities > Irfanview > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-16887 Classic Buffer Overflow vulnerability in Irfanview 4.53
In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x000000000001dcfc.
network
irfanview CWE-120
6.8
2019-07-04 CVE-2019-13243 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.52
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.
network
irfanview CWE-119
6.8
2019-07-04 CVE-2019-13242 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.52
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15769 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.50
IrfanView 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dds file, related to "Read Access Violation starting at FORMATS!ReadBLP_W+0x0000000000001b22."
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15768 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.50
IrfanView version 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address controls Branch Selection starting at image000007f7_42060000+0x0000000000094113."
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15767 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Cadimage and Irfanview
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at CADIMAGE+0x00000000003d5b52."
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15766 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Babacad4Image and Irfanview
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001f0a0."
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15765 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Cadimage and Irfanview
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at CADIMAGE+0x00000000003e9462."
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15764 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Babacad4Image and Irfanview
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001e6b0."
network
irfanview CWE-119
6.8
2017-10-22 CVE-2017-15763 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Babacad4Image and Irfanview
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001eca0."
network
irfanview CWE-119
6.8