Show filters
173 Total Results
Displaying 1-10 of 173
Sort by:
Attacker Value
Unknown

CVE-2024-11950

Disclosure Date: December 12, 2024 (last updated December 21, 2024)
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of RWZ files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22913.
0
Attacker Value
Unknown

CVE-2023-52174

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
Attacker Value
Unknown

CVE-2023-52173

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
Attacker Value
Unknown

CVE-2023-46587

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.
Attacker Value
Unknown

CVE-2021-28835

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.
Attacker Value
Unknown

CVE-2021-28427

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.
Attacker Value
Unknown

CVE-2020-23887

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.
Attacker Value
Unknown

CVE-2020-23886

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree.
Attacker Value
Unknown

CVE-2013-3492

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
XnView 2.03 has a stack-based buffer overflow vulnerability
Attacker Value
Unknown

CVE-2013-3493

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
XnView 2.03 has an integer overflow vulnerability