Vendor CVEs
Xnview
All CVEs
178 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-52174 | Cri | 0.64 | 9.8 | 0.01 | Dec 29, 2023 | XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6. | ||
| CVE-2023-52173 | Cri | 0.64 | 9.8 | 0.01 | Dec 29, 2023 | XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0. | ||
| CVE-2013-3493 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2020 | XnView 2.03 has an integer overflow vulnerability | ||
| CVE-2013-3492 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2020 | XnView 2.03 has a stack-based buffer overflow vulnerability | ||
| CVE-2013-3941 | Cri | 0.64 | 9.8 | 0.03 | Jan 2, 2020 | Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer… | ||
| CVE-2024-11950 | Hig | 0.57 | 8.8 | 0.00 | Dec 12, 2024 | XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in… | ||
| CVE-2023-46587 | Hig | 0.51 | 7.8 | 0.00 | Oct 27, 2023 | Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file. | ||
| CVE-2023-43251 | Hig | 0.51 | 7.8 | 0.01 | Oct 19, 2023 | XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution. | ||
| CVE-2023-43252 | Hig | 0.51 | 7.8 | 0.01 | Oct 19, 2023 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file. | ||
| CVE-2023-43250 | Hig | 0.51 | 7.8 | 0.01 | Oct 18, 2023 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution. | ||
| CVE-2021-28835 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2023 | Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file. | ||
| CVE-2021-28427 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2023 | Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file. | ||
| CVE-2013-3939 | Hig | 0.51 | 7.8 | 0.02 | Jan 2, 2020 | xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based… | ||
| CVE-2013-3937 | Hig | 0.51 | 7.8 | 0.02 | Jan 2, 2020 | Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file. | ||
| CVE-2013-3247 | Hig | 0.51 | 7.8 | 0.02 | Jan 2, 2020 | Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file. | ||
| CVE-2013-3246 | Hig | 0.51 | 7.8 | 0.02 | Jan 2, 2020 | Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file. | ||
| CVE-2019-17262 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2019 | XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0. | ||
| CVE-2019-17261 | Hig | 0.51 | 7.8 | 0.00 | Oct 8, 2019 | XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51. | ||
| CVE-2019-13262 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb. | ||
| CVE-2019-13261 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384. | ||
| CVE-2019-13260 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07. | ||
| CVE-2019-13259 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e566. | ||
| CVE-2019-13258 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165. | ||
| CVE-2019-13257 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa. | ||
| CVE-2019-13256 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e849. | ||
| CVE-2019-13255 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464. | ||
| CVE-2019-13254 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808. | ||
| CVE-2019-13253 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474. | ||
| CVE-2019-13085 | Hig | 0.51 | 7.8 | 0.01 | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa. | ||
| CVE-2019-13084 | Hig | 0.51 | 7.8 | 0.01 | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739. | ||
| CVE-2019-13083 | Hig | 0.51 | 7.8 | 0.01 | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a. | ||
| CVE-2019-9969 | Hig | 0.51 | 7.8 | 0.02 | Mar 24, 2019 | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399. | ||
| CVE-2019-9968 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem. | ||
| CVE-2019-9967 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString. | ||
| CVE-2019-9966 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c. | ||
| CVE-2019-9965 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap. | ||
| CVE-2019-9964 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlpNtMakeTemporaryKey. | ||
| CVE-2019-9963 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap. | ||
| CVE-2019-9962 | Hig | 0.51 | 7.8 | 0.01 | Mar 24, 2019 | XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy. | ||
| CVE-2018-15176 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file. | ||
| CVE-2018-15175 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file. | ||
| CVE-2018-15174 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO file. | ||
| CVE-2017-15789 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000048e7." | ||
| CVE-2017-15788 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x0000000000002d83." | ||
| CVE-2017-15787 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063." | ||
| CVE-2017-15786 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x00000000001a78db." | ||
| CVE-2017-15785 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation near NULL starting at Unknown Symbol @ 0x0000000000000000 called from… | ||
| CVE-2017-15784 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to an "Illegal Instruction Violation starting at xnview+0x0000000000370074." | ||
| CVE-2017-15783 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285ce1." | ||
| CVE-2017-15782 | Hig | 0.51 | 7.8 | 0.01 | Oct 22, 2017 | XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000032eb." |
- risk 0.64cvss 9.8epss 0.01
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
- risk 0.64cvss 9.8epss 0.01
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
- risk 0.64cvss 9.8epss 0.02
XnView 2.03 has an integer overflow vulnerability
- risk 0.64cvss 9.8epss 0.02
XnView 2.03 has a stack-based buffer overflow vulnerability
- risk 0.64cvss 9.8epss 0.03
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer…
- risk 0.57cvss 8.8epss 0.00
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in…
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.
- risk 0.51cvss 7.8epss 0.01
XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
- risk 0.51cvss 7.8epss 0.01
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.
- risk 0.51cvss 7.8epss 0.01
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.
- risk 0.51cvss 7.8epss 0.02
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based…
- risk 0.51cvss 7.8epss 0.02
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.
- risk 0.51cvss 7.8epss 0.02
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
- risk 0.51cvss 7.8epss 0.02
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.
- risk 0.51cvss 7.8epss 0.00
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.
- risk 0.51cvss 7.8epss 0.00
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e566.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e849.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.
- risk 0.51cvss 7.8epss 0.02
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.
- risk 0.51cvss 7.8epss 0.01
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.
- risk 0.51cvss 7.8epss 0.01
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap.
- risk 0.51cvss 7.8epss 0.01
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlpNtMakeTemporaryKey.
- risk 0.51cvss 7.8epss 0.01
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap.
- risk 0.51cvss 7.8epss 0.01
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy.
- risk 0.51cvss 7.8epss 0.01
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file.
- risk 0.51cvss 7.8epss 0.01
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file.
- risk 0.51cvss 7.8epss 0.01
XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO file.
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000048e7."
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x0000000000002d83."
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063."
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x00000000001a78db."
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation near NULL starting at Unknown Symbol @ 0x0000000000000000 called from…
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to an "Illegal Instruction Violation starting at xnview+0x0000000000370074."
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285ce1."
- risk 0.51cvss 7.8epss 0.01
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000032eb."
Page 1 of 4