VYPR

Irfanview

by IrfanView

CVEs (374)

  • CVE-2017-7721HigApr 30, 2017
    risk 0.51cvss 7.8epss 0.02

    IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.

  • CVE-2020-35133HigDec 16, 2020
    risk 0.49cvss 7.5epss 0.04

    irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.

  • CVE-2025-7233MedJul 21, 2025
    risk 0.36cvss 5.5epss 0.00

    IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this…

  • CVE-2024-31007MedOct 21, 2024
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability in IrfanView 32bit v.4.66 allows a local attacker to cause a denial of service via a crafted file. Affected component is IrfanView 32bit 4.66 with plugin formats.dll.

  • CVE-2024-44915MedAug 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2024-44914MedAug 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2024-44913MedAug 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2023-26974MedApr 4, 2023
    risk 0.36cvss 5.5epss 0.01

    Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.

  • CVE-2020-23563MedJul 18, 2022
    risk 0.36cvss 5.5epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.

  • CVE-2020-23562MedJul 18, 2022
    risk 0.36cvss 5.5epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.

  • CVE-2020-23561MedJul 18, 2022
    risk 0.36cvss 5.5epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.

  • CVE-2020-23567MedNov 5, 2021
    risk 0.36cvss 5.5epss 0.01

    Irfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer Divide By Zero starting at JPEG2000!ShowPlugInSaveOptions_W+0x00000000000082ea"

  • CVE-2020-23566MedNov 5, 2021
    risk 0.36cvss 5.5epss 0.01

    Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.

  • CVE-2021-29365MedSep 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS).

  • CVE-2021-29358MedSep 28, 2021
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR file.

  • CVE-2019-17257MedOct 8, 2019
    risk 0.36cvss 5.5epss 0.01

    IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR+0x000000000002af80.

  • CVE-2012-0897Jan 20, 2012
    risk 0.07cvss epss 0.53

    Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

  • CVE-2011-5233Oct 25, 2012
    risk 0.04cvss epss 0.09

    Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

  • CVE-2012-3585Jul 5, 2012
    risk 0.04cvss epss 0.08

    Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.

  • CVE-2008-0493Jan 30, 2008
    risk 0.04cvss epss 0.09

    fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.

Page 18 of 19