XnView records
174 published records for vendor xnview.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 14
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer133
- CWE-787 Out-of-bounds Write19
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-189 Numeric Errors4
- CWE-122 Heap-based Buffer Overflow1
- CWE-416 Use After Free1
The weakness classes this vendor ships most often: where to look.
CWEAll records
174 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2013-2577Proof of concept | Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.xnview · xnview · CWE-119 | Critical9.3 | — | 11.8% | Aug 9, 2013 |
40Plan | CVE-2010-1932Proof of concept | Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) fxnview · xnview · CWE-119 | Critical9.3 | — | 10.8% | Jun 16, 2010 |
40Plan | CVE-2012-4988Proof of concept | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attxnview · xnview · CWE-119 | Critical9.3 | — | 9.9% | Jul 9, 2014 |
40Plan | CVE-2013-3941No exploit | Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers xnview · xnview · CWE-787 | Critical9.8 | — | 2.8% | Jan 2, 2020 |
39Monitor | CVE-2013-3493No exploit | XnView 2.03 has an integer overflow vulnerabilityxnview · xnview · CWE-190 | Critical9.8 | — | 1.6% | Jan 27, 2020 |
39Monitor | CVE-2013-3492No exploit | XnView 2.03 has a stack-based buffer overflow vulnerabilityxnview · xnview · CWE-787 | Critical9.8 | — | 1.5% | Jan 27, 2020 |
39Monitor | CVE-2023-52174No exploit | XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.xnview · xnview classic · CWE-787 | Critical9.8 | — | 0.7% | Dec 29, 2023 |
39Monitor | CVE-2023-52173No exploit | XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.xnview · xnview classic · CWE-787 | Critical9.8 | — | 0.6% | Dec 29, 2023 |
38Monitor | CVE-2009-4001No exploit | Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, lxnview · xnview · CWE-189 | Critical9.3 | — | 4.6% | Mar 15, 2010 |
38Monitor | CVE-2012-0685No exploit | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD xnview · xnview · CWE-189 | Critical9.3 | — | 3.7% | May 9, 2012 |
38Monitor | CVE-2012-0684No exploit | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD xnview · xnview · CWE-189 | Critical9.3 | — | 3.7% | May 9, 2012 |
38Monitor | CVE-2013-3938No exploit | Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTxnview · xnview · CWE-189 | Critical9.3 | — | 3.5% | Mar 18, 2014 |
35Monitor | CVE-2024-11950No exploit | XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerabilityxnview · xnview · CWE-191 | High8.8 | — | 0.5% | Dec 11, 2024 |
33Monitor | CVE-2008-1461Proof of concept | Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the commandxnview · xnview · CWE-119 | High7.6 | — | 11.3% | Mar 24, 2008 |
32Monitor | CVE-2013-3247No exploit | Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressexnview · xnview · CWE-787 | High7.8 | — | 2.4% | Jan 2, 2020 |
32Monitor | CVE-2013-3246No exploit | Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer xnview · xnview · CWE-787 | High7.8 | — | 2.4% | Jan 2, 2020 |
32Monitor | CVE-2019-9969No exploit | XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other ixnview · xnview classic · CWE-119 | High7.8 | — | 2.0% | Mar 23, 2019 |
32Monitor | CVE-2013-3937No exploit | Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field inxnview · xnview · CWE-787 | High7.8 | — | 1.7% | Jan 2, 2020 |
32Monitor | CVE-2013-3939No exploit | xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers toxnview · xnview · CWE-787 | High7.8 | — | 1.7% | Jan 2, 2020 |
31Monitor | CVE-2017-9897No exploit | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV stxnview · xnview · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
31Monitor | CVE-2017-9896No exploit | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violationxnview · xnview · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
31Monitor | CVE-2017-9898No exploit | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV stxnview · xnview · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
31Monitor | CVE-2017-9899No exploit | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Addrxnview · xnview · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
31Monitor | CVE-2017-8381No exploit | XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled durxnview · xnview · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
31Monitor | CVE-2017-9529No exploit | XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV stxnview · xnview · CWE-119 | High7.8 | — | 1.6% | Jul 5, 2017 |
- CVE-2013-257741Plan
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
CriticalCVSS 9.3Proof of conceptEPSS 12%xnview · xnviewAug 9, 2013
- CVE-2010-193240Plan
Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) f
CriticalCVSS 9.3Proof of conceptEPSS 11%xnview · xnviewJun 16, 2010
- CVE-2012-498840Plan
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote att
CriticalCVSS 9.3Proof of conceptEPSS 10%xnview · xnviewJul 9, 2014
- CVE-2013-394140Plan
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers
CriticalCVSS 9.8No exploitEPSS 3%xnview · xnviewJan 2, 2020
- CVE-2013-349339Monitor
XnView 2.03 has an integer overflow vulnerability
CriticalCVSS 9.8No exploitEPSS 2%xnview · xnviewJan 27, 2020
- CVE-2013-349239Monitor
XnView 2.03 has a stack-based buffer overflow vulnerability
CriticalCVSS 9.8No exploitEPSS 2%xnview · xnviewJan 27, 2020
- CVE-2023-5217439Monitor
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.
CriticalCVSS 9.8No exploitEPSS 1%xnview · xnview classicDec 29, 2023
- CVE-2023-5217339Monitor
XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.
CriticalCVSS 9.8No exploitEPSS 1%xnview · xnview classicDec 29, 2023
- CVE-2009-400138Monitor
Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, l
CriticalCVSS 9.3No exploitEPSS 5%xnview · xnviewMar 15, 2010
- CVE-2012-068538Monitor
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD
CriticalCVSS 9.3No exploitEPSS 4%xnview · xnviewMay 9, 2012
- CVE-2012-068438Monitor
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD
CriticalCVSS 9.3No exploitEPSS 4%xnview · xnviewMay 9, 2012
- CVE-2013-393838Monitor
Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENT
CriticalCVSS 9.3No exploitEPSS 3%xnview · xnviewMar 18, 2014
- CVE-2024-1195035Monitor
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 0%xnview · xnviewDec 11, 2024
- CVE-2008-146133Monitor
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command
HighCVSS 7.6Proof of conceptEPSS 11%xnview · xnviewMar 24, 2008
- CVE-2013-324732Monitor
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compresse
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJan 2, 2020
- CVE-2013-324632Monitor
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJan 2, 2020
- CVE-2019-996932Monitor
XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
HighCVSS 7.8No exploitEPSS 2%xnview · xnview classicMar 23, 2019
- CVE-2013-393732Monitor
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJan 2, 2020
- CVE-2013-393932Monitor
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJan 2, 2020
- CVE-2017-989731Monitor
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJul 5, 2017
- CVE-2017-989631Monitor
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJul 5, 2017
- CVE-2017-989831Monitor
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJul 5, 2017
- CVE-2017-989931Monitor
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Addr
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJul 5, 2017
- CVE-2017-838131Monitor
XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled dur
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJul 5, 2017
- CVE-2017-952931Monitor
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st
HighCVSS 7.8No exploitEPSS 2%xnview · xnviewJul 5, 2017