VYPR

Irfanview

by IrfanView

CVEs (375)

  • CVE-2024-5874HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-6812HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-6811HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2023-24304HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.

  • CVE-2020-23560HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.

  • CVE-2020-23559HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f.

  • CVE-2020-23558HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b.

  • CVE-2020-23557HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d.

  • CVE-2020-23556HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28.

  • CVE-2020-23555HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.

  • CVE-2020-23554HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20.

  • CVE-2020-23553HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007d33.

  • CVE-2020-23552HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e62.

  • CVE-2020-23551HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30.

  • CVE-2020-23550HigSep 16, 2022
    risk 0.51cvss 7.8epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e82.

  • CVE-2021-46064HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.

  • CVE-2020-23545HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.

  • CVE-2020-23565HigNov 5, 2021
    risk 0.51cvss 7.8epss 0.01

    Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".

  • CVE-2020-23549HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".

  • CVE-2020-23546HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.

Page 10 of 19