Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-05 CVE-2017-9529 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.40
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004efd."
local
low complexity
xnview CWE-119
7.8
2017-07-05 CVE-2017-9528 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview FPX and Irfanview
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53."
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-8826 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Faststone Image Viewer 6.2
FastStone Image Viewer 6.2 has a "User Mode Write AV" issue, possibly related to the jpeg_mem_term function in jmemnobs.c in libjpeg.
local
low complexity
faststone CWE-119
7.8
2017-07-05 CVE-2017-8803 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mh-Nexus HEX Editor 0.9.5
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue.
local
low complexity
mh-nexus CWE-119
7.8
2017-07-05 CVE-2017-8785 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Faststone Image Viewer 6.2
FastStone Image Viewer 6.2 has a "Data from Faulting Address may be used as a return value" issue.
local
low complexity
faststone CWE-119
7.8
2017-07-05 CVE-2017-8781 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.40
XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted JPEG 2000 file that is mishandled during the opening of a directory in "Browser" mode, because of a "Stack Buffer Overrun" issue.
local
low complexity
xnview CWE-119
7.8
2017-07-05 CVE-2017-8766 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) allows remote attackers to execute code via a crafted .mov file, because of a "User Mode Write AV near NULL" issue.
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-8381 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.40
XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled during the opening of a directory in "Browser" mode, because of a "User Mode Write AV near NULL" in XnView.exe.
local
low complexity
xnview CWE-119
7.8
2017-07-05 CVE-2017-8370 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview FPX and Irfanview
IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different vulnerability than CVE-2017-7721.
local
low complexity
irfanview CWE-119
7.8
2017-07-05 CVE-2017-8369 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.
local
low complexity
irfanview CWE-119
7.8