Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-11950

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of RWZ files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22913.
0
Attacker Value
Unknown

CVE-2023-52174

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
Attacker Value
Unknown

CVE-2023-52173

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
Attacker Value
Unknown

CVE-2019-9967

Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.
0
Attacker Value
Unknown

CVE-2019-9969

Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.
0
Attacker Value
Unknown

CVE-2019-9966

Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.
0
Attacker Value
Unknown

CVE-2019-9968

Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem.
0