Critical severity9.8NVD Advisory· Published Jan 2, 2020· Updated Jun 16, 2026
CVE-2013-3941
CVE-2013-3941
Description
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- newsgroup.xnview.com/viewtopic.phpnvdPermissions RequiredVendor Advisory
- secunia.com/advisories/52101nvdNot ApplicableThird Party Advisory
News mentions
0No linked articles in our index yet.