Irfanview
by IrfanView
CVEs (375)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5874 | Hig | 0.51 | 7.8 | 0.01 | Nov 22, 2024 | IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must… | ||
| CVE-2024-6812 | Hig | 0.51 | 7.8 | 0.01 | Aug 21, 2024 | IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must… | ||
| CVE-2024-6811 | Hig | 0.51 | 7.8 | 0.01 | Aug 21, 2024 | IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must… | ||
| CVE-2023-24304 | Hig | 0.51 | 7.8 | 0.00 | Mar 28, 2023 | Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file. | ||
| CVE-2020-23560 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab. | ||
| CVE-2020-23559 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f. | ||
| CVE-2020-23558 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b. | ||
| CVE-2020-23557 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d. | ||
| CVE-2020-23556 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28. | ||
| CVE-2020-23555 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e. | ||
| CVE-2020-23554 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20. | ||
| CVE-2020-23553 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007d33. | ||
| CVE-2020-23552 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e62. | ||
| CVE-2020-23551 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30. | ||
| CVE-2020-23550 | Hig | 0.51 | 7.8 | 0.00 | Sep 16, 2022 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e82. | ||
| CVE-2021-46064 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2022 | IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image. | ||
| CVE-2020-23545 | Hig | 0.51 | 7.8 | 0.01 | Dec 15, 2021 | IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531. | ||
| CVE-2020-23565 | Hig | 0.51 | 7.8 | 0.01 | Nov 5, 2021 | Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850". | ||
| CVE-2020-23549 | Hig | 0.51 | 7.8 | 0.01 | Oct 28, 2021 | IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6". | ||
| CVE-2020-23546 | Hig | 0.51 | 7.8 | 0.01 | Oct 28, 2021 | IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981. |
- risk 0.51cvss 7.8epss 0.01
IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…
- risk 0.51cvss 7.8epss 0.01
IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…
- risk 0.51cvss 7.8epss 0.01
IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…
- risk 0.51cvss 7.8epss 0.00
Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007d33.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e62.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30.
- risk 0.51cvss 7.8epss 0.00
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e82.
- risk 0.51cvss 7.8epss 0.01
IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.
- risk 0.51cvss 7.8epss 0.01
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.
- risk 0.51cvss 7.8epss 0.01
Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".
- risk 0.51cvss 7.8epss 0.01
IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".
- risk 0.51cvss 7.8epss 0.01
IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.
Page 10 of 19