Записи XnView
174 опубликованных записей вендора xnview.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 14
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer133
- CWE-787 Out-of-bounds Write19
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-189 Numeric Errors4
- CWE-122 Heap-based Buffer Overflow1
- CWE-416 Use After Free1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
174 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2013-2577Proof of concept | Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.xnview · xnview · CWE-119 | Критическая9,3 | — | 11,8 % | 9 авг. 2013 г. |
40В плане | CVE-2010-1932Proof of concept | Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) fxnview · xnview · CWE-119 | Критическая9,3 | — | 10,8 % | 16 июн. 2010 г. |
40В плане | CVE-2012-4988Proof of concept | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attxnview · xnview · CWE-119 | Критическая9,3 | — | 9,9 % | 9 июл. 2014 г. |
40В плане | CVE-2013-3941Эксплойта нет | Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers xnview · xnview · CWE-787 | Критическая9,8 | — | 2,8 % | 2 янв. 2020 г. |
39Наблюдать | CVE-2013-3493Эксплойта нет | XnView 2.03 has an integer overflow vulnerabilityxnview · xnview · CWE-190 | Критическая9,8 | — | 1,6 % | 27 янв. 2020 г. |
39Наблюдать | CVE-2013-3492Эксплойта нет | XnView 2.03 has a stack-based buffer overflow vulnerabilityxnview · xnview · CWE-787 | Критическая9,8 | — | 1,5 % | 27 янв. 2020 г. |
39Наблюдать | CVE-2023-52174Эксплойта нет | XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.xnview · xnview classic · CWE-787 | Критическая9,8 | — | 0,7 % | 29 дек. 2023 г. |
39Наблюдать | CVE-2023-52173Эксплойта нет | XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.xnview · xnview classic · CWE-787 | Критическая9,8 | — | 0,6 % | 29 дек. 2023 г. |
38Наблюдать | CVE-2009-4001Эксплойта нет | Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, lxnview · xnview · CWE-189 | Критическая9,3 | — | 4,6 % | 15 мар. 2010 г. |
38Наблюдать | CVE-2012-0685Эксплойта нет | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD xnview · xnview · CWE-189 | Критическая9,3 | — | 3,7 % | 9 мая 2012 г. |
38Наблюдать | CVE-2012-0684Эксплойта нет | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD xnview · xnview · CWE-189 | Критическая9,3 | — | 3,7 % | 9 мая 2012 г. |
38Наблюдать | CVE-2013-3938Эксплойта нет | Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTxnview · xnview · CWE-189 | Критическая9,3 | — | 3,5 % | 18 мар. 2014 г. |
35Наблюдать | CVE-2024-11950Эксплойта нет | XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerabilityxnview · xnview · CWE-191 | Высокая8,8 | — | 0,5 % | 11 дек. 2024 г. |
33Наблюдать | CVE-2008-1461Proof of concept | Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the commandxnview · xnview · CWE-119 | Высокая7,6 | — | 11,3 % | 24 мар. 2008 г. |
32Наблюдать | CVE-2013-3247Эксплойта нет | Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressexnview · xnview · CWE-787 | Высокая7,8 | — | 2,4 % | 2 янв. 2020 г. |
32Наблюдать | CVE-2013-3246Эксплойта нет | Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer xnview · xnview · CWE-787 | Высокая7,8 | — | 2,4 % | 2 янв. 2020 г. |
32Наблюдать | CVE-2019-9969Эксплойта нет | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other ixnview · xnview classic · CWE-119 | Высокая7,8 | — | 2,0 % | 23 мар. 2019 г. |
32Наблюдать | CVE-2013-3937Эксплойта нет | Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field inxnview · xnview · CWE-787 | Высокая7,8 | — | 1,7 % | 2 янв. 2020 г. |
32Наблюдать | CVE-2013-3939Эксплойта нет | xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers toxnview · xnview · CWE-787 | Высокая7,8 | — | 1,7 % | 2 янв. 2020 г. |
31Наблюдать | CVE-2017-9897Эксплойта нет | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV stxnview · xnview · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
31Наблюдать | CVE-2017-9896Эксплойта нет | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violationxnview · xnview · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
31Наблюдать | CVE-2017-9898Эксплойта нет | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV stxnview · xnview · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
31Наблюдать | CVE-2017-9899Эксплойта нет | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Addrxnview · xnview · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
31Наблюдать | CVE-2017-8381Эксплойта нет | XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled durxnview · xnview · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
31Наблюдать | CVE-2017-9529Эксплойта нет | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV stxnview · xnview · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
- CVE-2013-257741В плане
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
КритическаяCVSS 9,3Proof of conceptEPSS 12 %xnview · xnview9 авг. 2013 г.
- CVE-2010-193240В плане
Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) f
КритическаяCVSS 9,3Proof of conceptEPSS 11 %xnview · xnview16 июн. 2010 г.
- CVE-2012-498840В плане
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote att
КритическаяCVSS 9,3Proof of conceptEPSS 10 %xnview · xnview9 июл. 2014 г.
- CVE-2013-394140В плане
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xnview · xnview2 янв. 2020 г.
- CVE-2013-349339Наблюдать
XnView 2.03 has an integer overflow vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %xnview · xnview27 янв. 2020 г.
- CVE-2013-349239Наблюдать
XnView 2.03 has a stack-based buffer overflow vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %xnview · xnview27 янв. 2020 г.
- CVE-2023-5217439Наблюдать
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xnview · xnview classic29 дек. 2023 г.
- CVE-2023-5217339Наблюдать
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xnview · xnview classic29 дек. 2023 г.
- CVE-2009-400138Наблюдать
Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, l
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %xnview · xnview15 мар. 2010 г.
- CVE-2012-068538Наблюдать
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %xnview · xnview9 мая 2012 г.
- CVE-2012-068438Наблюдать
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %xnview · xnview9 мая 2012 г.
- CVE-2013-393838Наблюдать
Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENT
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %xnview · xnview18 мар. 2014 г.
- CVE-2024-1195035Наблюдать
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %xnview · xnview11 дек. 2024 г.
- CVE-2008-146133Наблюдать
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command
ВысокаяCVSS 7,6Proof of conceptEPSS 11 %xnview · xnview24 мар. 2008 г.
- CVE-2013-324732Наблюдать
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compresse
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview2 янв. 2020 г.
- CVE-2013-324632Наблюдать
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview2 янв. 2020 г.
- CVE-2019-996932Наблюдать
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview classic23 мар. 2019 г.
- CVE-2013-393732Наблюдать
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview2 янв. 2020 г.
- CVE-2013-393932Наблюдать
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview2 янв. 2020 г.
- CVE-2017-989731Наблюдать
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview5 июл. 2017 г.
- CVE-2017-989631Наблюдать
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview5 июл. 2017 г.
- CVE-2017-989831Наблюдать
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview5 июл. 2017 г.
- CVE-2017-989931Наблюдать
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Addr
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview5 июл. 2017 г.
- CVE-2017-838131Наблюдать
XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled dur
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview5 июл. 2017 г.
- CVE-2017-952931Наблюдать
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %xnview · xnview5 июл. 2017 г.