Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-11950
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of RWZ files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22913.
0
Attacker Value
Unknown
CVE-2023-52174
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
0
Attacker Value
Unknown
CVE-2023-52173
Disclosure Date: December 29, 2023 (last updated January 05, 2024)
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
0
Attacker Value
Unknown
CVE-2019-9967
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.
0
Attacker Value
Unknown
CVE-2019-9969
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.
0
Attacker Value
Unknown
CVE-2019-9966
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.
0
Attacker Value
Unknown
CVE-2019-9968
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem.
0