Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-22 CVE-2017-15739 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Cadimage and Irfanview
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at CADIMAGE+0x00000000000042d5."
local
low complexity
irfanview CWE-119
7.8
2017-10-22 CVE-2017-15738 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Cadimage and Irfanview
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d22d8."
local
low complexity
irfanview CWE-119
7.8
2017-10-22 CVE-2017-15737 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview Cadimage and Irfanview
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d246f."
local
low complexity
irfanview CWE-119
7.8
2017-10-22 CVE-2017-15723 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.
network
low complexity
irssi debian CWE-476
7.5
2017-10-22 CVE-2017-15721 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference.
network
low complexity
irssi debian CWE-476
7.5
2017-10-22 CVE-2017-15228 Out-of-bounds Read vulnerability in Irssi
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
network
low complexity
irssi CWE-125
7.5
2017-10-22 CVE-2017-15227 Use After Free vulnerability in Irssi
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.
network
low complexity
irssi CWE-416
7.5
2017-10-22 CVE-2017-15803 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.43
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000150."
local
low complexity
xnview CWE-119
7.8
2017-10-22 CVE-2017-15802 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.43
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000087."
local
low complexity
xnview CWE-119
7.8
2017-10-22 CVE-2017-15801 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.43
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResSearchResourceInsideDirectory+0x000000000000029e."
local
low complexity
xnview CWE-119
7.8