VYPR

Vendor CVEs

IrfanView

All CVEs

385 total · sorted by risk
  • CVE-2021-46064HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.

  • CVE-2020-23545HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.

  • CVE-2020-23565HigNov 5, 2021
    risk 0.51cvss 7.8epss 0.01

    Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".

  • CVE-2020-23549HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".

  • CVE-2020-23546HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.

  • CVE-2021-29367HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file.

  • CVE-2021-29366HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

  • CVE-2021-29364HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in Formats!ReadRAS_W+0x1001 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

  • CVE-2021-29363HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa74 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.0xa74

  • CVE-2021-29362HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in FORMATS!ReadRAS_W+0xa30 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

  • CVE-2021-29361HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x340 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

  • CVE-2021-29360HigSep 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in FORMATS!Read_Utah_RLE+0x37a of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.

  • CVE-2020-13906HigJun 10, 2020
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038eb7.

  • CVE-2013-3946HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.

  • CVE-2013-3945HigJan 2, 2020
    risk 0.51cvss 7.8epss 0.02

    The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.

  • CVE-2019-17258HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000000839c.

  • CVE-2019-17256HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at DPX!ReadDPX_W+0x0000000000001203.

  • CVE-2019-17255HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at EXR!ReadEXR+0x0000000000010836.

  • CVE-2019-17254HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at FORMATS!Read_BadPNG+0x0000000000000101.

  • CVE-2019-17253HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at JPEG_LS+0x000000000000a6b8.

  • CVE-2019-17252HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.03

    IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!Read_BadPNG+0x0000000000000115.

  • CVE-2019-17251HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d43.

  • CVE-2019-17250HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x00000000000042f5.

  • CVE-2019-17249HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000d57b.

  • CVE-2019-17248HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x00000000000025b6.

  • CVE-2019-17247HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x0000000000007da8.

  • CVE-2019-17246HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000258c.

  • CVE-2019-17245HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x0000000000004359.

  • CVE-2019-17244HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000001d8a.

  • CVE-2019-17243HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000003155.

  • CVE-2019-17242HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000966f.

  • CVE-2019-17241HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000d563.

  • CVE-2019-16887HigSep 25, 2019
    risk 0.51cvss 7.8epss 0.02

    In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x000000000001dcfc.

  • CVE-2019-13243HigJul 4, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.

  • CVE-2019-13242HigJul 4, 2019
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.

  • CVE-2017-15769HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dds file, related to "Read Access Violation starting at FORMATS!ReadBLP_W+0x0000000000001b22."

  • CVE-2017-15768HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView version 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address controls Branch Selection starting at image000007f7_42060000+0x0000000000094113."

  • CVE-2017-15767HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at CADIMAGE+0x00000000003d5b52."

  • CVE-2017-15766HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at…

  • CVE-2017-15765HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call…

  • CVE-2017-15764HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001e6b0."

  • CVE-2017-15763HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at…

  • CVE-2017-15762HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001f31b."

  • CVE-2017-15761HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ecaa."

  • CVE-2017-15760HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ce82."

  • CVE-2017-15759HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001b3f3."

  • CVE-2017-15758HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at…

  • CVE-2017-15757HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at…

  • CVE-2017-15756HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at…

  • CVE-2017-15755HigOct 22, 2017
    risk 0.51cvss 7.8epss 0.02

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at…

Page 5 of 8