VYPR

Vendor CVEs

IrfanView

All CVEs

385 total · sorted by risk
  • CVE-2025-7233MedJul 21, 2025
    risk 0.36cvss 5.5epss 0.00

    IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this…

  • CVE-2024-31007MedOct 21, 2024
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow vulnerability in IrfanView 32bit v.4.66 allows a local attacker to cause a denial of service via a crafted file. Affected component is IrfanView 32bit 4.66 with plugin formats.dll.

  • CVE-2024-44915MedAug 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2024-44914MedAug 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2024-44913MedAug 28, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2023-26974MedApr 4, 2023
    risk 0.36cvss 5.5epss 0.01

    Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.

  • CVE-2020-23563MedJul 18, 2022
    risk 0.36cvss 5.5epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.

  • CVE-2020-23562MedJul 18, 2022
    risk 0.36cvss 5.5epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.

  • CVE-2020-23561MedJul 18, 2022
    risk 0.36cvss 5.5epss 0.00

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.

  • CVE-2020-23567MedNov 5, 2021
    risk 0.36cvss 5.5epss 0.01

    Irfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer Divide By Zero starting at JPEG2000!ShowPlugInSaveOptions_W+0x00000000000082ea"

  • CVE-2020-23566MedNov 5, 2021
    risk 0.36cvss 5.5epss 0.01

    Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.

  • CVE-2021-29365MedSep 28, 2021
    risk 0.36cvss 5.5epss 0.01

    Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCrop_W component. This can cause a denial of service (DOS).

  • CVE-2021-29358MedSep 28, 2021
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR file.

  • CVE-2019-17257MedOct 8, 2019
    risk 0.36cvss 5.5epss 0.01

    IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR+0x000000000002af80.

  • CVE-2012-0897Jan 20, 2012
    risk 0.07cvss epss 0.53

    Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

  • CVE-2012-0025Nov 2, 2012
    risk 0.04cvss epss 0.06

    Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.

  • CVE-2011-5233Oct 25, 2012
    risk 0.04cvss epss 0.09

    Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

  • CVE-2012-3585Jul 5, 2012
    risk 0.04cvss epss 0.08

    Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.

  • CVE-2012-0278Apr 18, 2012
    risk 0.04cvss epss 0.10

    Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.

  • CVE-2008-0493Jan 30, 2008
    risk 0.04cvss epss 0.09

    fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.

  • CVE-2007-2363Apr 30, 2007
    risk 0.04cvss epss 0.09

    Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.

  • CVE-2007-1948Apr 11, 2007
    risk 0.04cvss epss 0.08

    Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and…

  • CVE-2007-1867Apr 4, 2007
    risk 0.04cvss epss 0.08

    Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.

  • CVE-2006-4374Aug 26, 2006
    risk 0.03cvss epss 0.03

    IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.

  • CVE-1999-1112Nov 9, 1999
    risk 0.03cvss epss 0.04

    Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.

  • CVE-2013-5351Feb 14, 2014
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.

  • CVE-2013-6932Dec 28, 2013
    risk 0.00cvss epss 0.06

    Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.

  • CVE-2012-5904Nov 17, 2012
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

  • CVE-2010-1510May 14, 2010
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.

  • CVE-2010-1509May 14, 2010
    risk 0.00cvss epss 0.04

    IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based…

  • CVE-2009-2118Jun 18, 2009
    risk 0.00cvss epss 0.03

    Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.

  • CVE-2009-0197Apr 9, 2009
    risk 0.00cvss epss 0.05

    Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.

  • CVE-2007-4343Oct 16, 2007
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.

  • CVE-2007-1245Mar 3, 2007
    risk 0.00cvss epss 0.01

    IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.

  • CVE-2006-4231Aug 18, 2006
    risk 0.00cvss epss 0.01

    IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.

Page 8 of 8