VYPR

Flashpix Plugin

Sign in to watch

by IrfanView

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2012-00250.050.22Nov 2, 2012Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.
CVE-2012-02780.040.18Apr 18, 2012Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.