Skip to content
Noroxi

XnView records

174 published records for vendor xnview.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
14
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

174 records
  • Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.

    CriticalCVSS 9.3Proof of conceptEPSS 12%

    xnview · xnviewAug 9, 2013

  • Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) f

    CriticalCVSS 9.3Proof of conceptEPSS 11%

    xnview · xnviewJun 16, 2010

  • Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote att

    CriticalCVSS 9.3Proof of conceptEPSS 10%

    xnview · xnviewJul 9, 2014

  • Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers

    CriticalCVSS 9.8No exploitEPSS 3%

    xnview · xnviewJan 2, 2020

  • CVE-2013-3493
    39Monitor

    XnView 2.03 has an integer overflow vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    xnview · xnviewJan 27, 2020

  • CVE-2013-3492
    39Monitor

    XnView 2.03 has a stack-based buffer overflow vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    xnview · xnviewJan 27, 2020

  • XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6.

    CriticalCVSS 9.8No exploitEPSS 1%

    xnview · xnview classicDec 29, 2023

  • XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3ADBD0.

    CriticalCVSS 9.8No exploitEPSS 1%

    xnview · xnview classicDec 29, 2023

  • CVE-2009-4001
    38Monitor

    Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, l

    CriticalCVSS 9.3No exploitEPSS 5%

    xnview · xnviewMar 15, 2010

  • CVE-2012-0685
    38Monitor

    Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD

    CriticalCVSS 9.3No exploitEPSS 4%

    xnview · xnviewMay 9, 2012

  • CVE-2012-0684
    38Monitor

    Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD

    CriticalCVSS 9.3No exploitEPSS 4%

    xnview · xnviewMay 9, 2012

  • CVE-2013-3938
    38Monitor

    Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENT

    CriticalCVSS 9.3No exploitEPSS 3%

    xnview · xnviewMar 18, 2014

  • XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    xnview · xnviewDec 11, 2024

  • CVE-2008-1461
    33Monitor

    Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command

    HighCVSS 7.6Proof of conceptEPSS 11%

    xnview · xnviewMar 24, 2008

  • CVE-2013-3247
    32Monitor

    Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compresse

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJan 2, 2020

  • CVE-2013-3246
    32Monitor

    Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJan 2, 2020

  • CVE-2019-9969
    32Monitor

    XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other i

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnview classicMar 23, 2019

  • CVE-2013-3937
    32Monitor

    Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJan 2, 2020

  • CVE-2013-3939
    32Monitor

    xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJan 2, 2020

  • CVE-2017-9897
    31Monitor

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJul 5, 2017

  • CVE-2017-9896
    31Monitor

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJul 5, 2017

  • CVE-2017-9898
    31Monitor

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJul 5, 2017

  • CVE-2017-9899
    31Monitor

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Addr

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJul 5, 2017

  • CVE-2017-8381
    31Monitor

    XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled dur

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJul 5, 2017

  • CVE-2017-9529
    31Monitor

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV st

    HighCVSS 7.8No exploitEPSS 2%

    xnview · xnviewJul 5, 2017