MidnightBSD

Advisories for irfanview

CVE-1999-1112 HIGH

Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
irfanview irfanview *
CVE-2006-4231 LOW

IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
irfanview irfanview 3.98
CVE-2006-4374 LOW

IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.

CVSS 2.0

Severity: LOW

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
irfanview irfanview 3.98
CVE-2007-1245 MEDIUM

IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 3.99
CVE-2007-1867 HIGH

Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
irfanview irfanview 3.99
CVE-2007-1948 HIGH

Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
irfanview irfanview 3.99
CVE-2007-2363 HIGH

Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
irfanview irfanview *
CVE-2007-4343 MEDIUM

Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 3.99
irfanview irfanview 4.00
CVE-2008-0493 HIGH

fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.10
CVE-2009-0197 HIGH

Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
irfanview formats 4.10
irfanview formats 4.00
irfanview formats 4.20
irfanview formats *
CVE-2009-2118 MEDIUM

Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
irfanview irfanview 4.23
CVE-2010-1509 MEDIUM

IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 3.07
irfanview irfanview 2.52
irfanview irfanview 2.63
irfanview irfanview 1.98a
irfanview irfanview 3.60
irfanview irfanview 2.00
irfanview irfanview 2.55
irfanview irfanview 3.80
irfanview irfanview 3.20
irfanview irfanview 2.65
irfanview irfanview 1.70
irfanview irfanview 3.17
irfanview irfanview 3.21
irfanview irfanview 2.92
irfanview irfanview 2.85
irfanview irfanview 3.36
irfanview irfanview *
irfanview irfanview 3.97
irfanview irfanview 3.92
irfanview irfanview 2.35
irfanview irfanview 2.83
irfanview irfanview 2.22
irfanview irfanview 1.90
irfanview irfanview 2.80
irfanview irfanview 2.25
irfanview irfanview 3.50
irfanview irfanview 1.98
irfanview irfanview 1.80
irfanview irfanview 3.35
irfanview irfanview 2.62
irfanview irfanview 3.10
irfanview irfanview 3.30
irfanview irfanview 1.97
irfanview irfanview 2.40
irfanview irfanview 3.91
irfanview irfanview 3.00
irfanview irfanview 3.70
irfanview irfanview 2.30
irfanview irfanview 3.15
irfanview irfanview 2.90
irfanview irfanview 2.12
irfanview irfanview 3.99
irfanview irfanview 2.50
irfanview irfanview 3.51
irfanview irfanview 4.22
irfanview irfanview 2.15
irfanview irfanview 2.37
irfanview irfanview 3.25
irfanview irfanview 2.10
irfanview irfanview 2.98
irfanview irfanview 3.85
irfanview irfanview 2.68
irfanview irfanview 2.18
irfanview irfanview 2.66
irfanview irfanview 3.05
irfanview irfanview 3.95
irfanview irfanview 4.00
irfanview irfanview 1.99
irfanview irfanview 2.32
irfanview irfanview 1.85
irfanview irfanview 4.10
irfanview irfanview 1.95
irfanview irfanview 2.20
irfanview irfanview 1.75
irfanview irfanview 3.12
irfanview irfanview 4.20
irfanview irfanview 2.05
irfanview irfanview 3.75
irfanview irfanview 3.98
irfanview irfanview 2.60
irfanview irfanview 2.82
irfanview irfanview 3.61
irfanview irfanview 2.17
irfanview irfanview 2.07
irfanview irfanview 2.97
irfanview irfanview 3.02
irfanview irfanview 3.33
irfanview irfanview 2.95
irfanview irfanview 2.27
irfanview irfanview 4.23
irfanview irfanview 3.90
CVE-2010-1510 MEDIUM

Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 3.07
irfanview irfanview 2.63
irfanview irfanview 2.52
irfanview irfanview 1.98a
irfanview irfanview 2.00
irfanview irfanview 3.60
irfanview irfanview 2.55
irfanview irfanview 3.80
irfanview irfanview 3.20
irfanview irfanview 1.70
irfanview irfanview 2.65
irfanview irfanview 2.92
irfanview irfanview 3.17
irfanview irfanview 3.21
irfanview irfanview 2.85
irfanview irfanview 3.36
irfanview irfanview *
irfanview irfanview 3.97
irfanview irfanview 3.92
irfanview irfanview 2.35
irfanview irfanview 2.22
irfanview irfanview 2.83
irfanview irfanview 1.90
irfanview irfanview 2.80
irfanview irfanview 2.25
irfanview irfanview 3.50
irfanview irfanview 1.98
irfanview irfanview 1.80
irfanview irfanview 3.35
irfanview irfanview 2.62
irfanview irfanview 3.10
irfanview irfanview 3.30
irfanview irfanview 1.97
irfanview irfanview 2.40
irfanview irfanview 3.00
irfanview irfanview 3.91
irfanview irfanview 3.70
irfanview irfanview 2.30
irfanview irfanview 3.15
irfanview irfanview 2.90
irfanview irfanview 2.12
irfanview irfanview 3.99
irfanview irfanview 2.50
irfanview irfanview 3.51
irfanview irfanview 4.22
irfanview irfanview 2.15
irfanview irfanview 2.37
irfanview irfanview 3.25
irfanview irfanview 2.10
irfanview irfanview 2.98
irfanview irfanview 3.85
irfanview irfanview 2.68
irfanview irfanview 2.18
irfanview irfanview 2.66
irfanview irfanview 3.05
irfanview irfanview 3.95
irfanview irfanview 4.00
irfanview irfanview 1.99
irfanview irfanview 1.85
irfanview irfanview 2.32
irfanview irfanview 4.10
irfanview irfanview 1.95
irfanview irfanview 2.20
irfanview irfanview 1.75
irfanview irfanview 3.12
irfanview irfanview 4.20
irfanview irfanview 2.05
irfanview irfanview 3.75
irfanview irfanview 3.98
irfanview irfanview 2.60
irfanview irfanview 2.82
irfanview irfanview 3.61
irfanview irfanview 2.17
irfanview irfanview 2.07
irfanview irfanview 2.97
irfanview irfanview 2.95
irfanview irfanview 3.02
irfanview irfanview 3.33
irfanview irfanview 2.27
irfanview irfanview 4.23
irfanview irfanview 3.90
CVE-2011-5233 MEDIUM

Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.25
irfanview irfanview 3.92
irfanview irfanview 3.99
irfanview irfanview 4.10
irfanview irfanview 4.20
irfanview irfanview 3.98
irfanview irfanview 4.27
irfanview irfanview *
irfanview irfanview 3.97
irfanview irfanview 3.95
irfanview irfanview 4.28
irfanview irfanview 3.91
irfanview irfanview 4.00
irfanview irfanview 4.23
irfanview irfanview 3.90
CVE-2012-0025 MEDIUM

Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
irfanview flashpix_plugin 4.2.2.0
CVE-2012-0278 HIGH

Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview flashpix_plugin 4.32
irfanview flashpix_plugin *
CVE-2012-0897 MEDIUM

Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 3.07
irfanview irfanview 2.52
irfanview irfanview 2.63
irfanview irfanview 1.98a
irfanview irfanview 3.60
irfanview irfanview 2.00
irfanview irfanview 2.55
irfanview irfanview 4.30
irfanview irfanview 3.80
irfanview irfanview 3.20
irfanview irfanview 2.65
irfanview irfanview 1.70
irfanview irfanview 3.17
irfanview irfanview 2.92
irfanview irfanview 3.21
irfanview irfanview 2.85
irfanview irfanview 3.36
irfanview irfanview *
irfanview irfanview 3.97
irfanview irfanview 3.92
irfanview irfanview 2.35
irfanview irfanview 2.83
irfanview irfanview 2.22
irfanview irfanview 1.90
irfanview irfanview 2.80
irfanview irfanview 2.25
irfanview irfanview 3.50
irfanview irfanview 1.98
irfanview irfanview 1.80
irfanview irfanview 3.35
irfanview irfanview 2.62
irfanview irfanview 3.10
irfanview irfanview 3.30
irfanview irfanview 1.97
irfanview irfanview 2.40
irfanview irfanview 3.00
irfanview irfanview 3.91
irfanview irfanview 3.70
irfanview irfanview 2.30
irfanview irfanview 3.15
irfanview irfanview 2.90
irfanview irfanview 2.12
irfanview irfanview 4.25
irfanview irfanview 3.99
irfanview irfanview 2.50
irfanview irfanview 3.51
irfanview irfanview 4.22
irfanview irfanview 2.15
irfanview irfanview 3.25
irfanview irfanview 2.37
irfanview irfanview 2.10
irfanview irfanview 2.98
irfanview irfanview 3.85
irfanview irfanview 2.68
irfanview irfanview 4.27
irfanview irfanview 2.18
irfanview irfanview 3.0.7
irfanview irfanview 2.66
irfanview irfanview 3.95
irfanview irfanview 3.05
irfanview irfanview 4.00
irfanview irfanview 4.28
irfanview irfanview 1.99
irfanview irfanview 1.85
irfanview irfanview 2.32
irfanview irfanview 4.10
irfanview irfanview 1.95
irfanview irfanview 2.20
irfanview irfanview 1.75
irfanview irfanview 3.12
irfanview irfanview 4.20
irfanview irfanview 3.75
irfanview irfanview 2.05
irfanview irfanview 3.98
irfanview irfanview 2.60
irfanview irfanview 2.82
irfanview irfanview 3.61
irfanview irfanview 2.07
irfanview irfanview 2.17
irfanview irfanview 2.97
irfanview irfanview 2.95
irfanview irfanview 3.02
irfanview irfanview 3.33
irfanview irfanview 2.27
irfanview irfanview 4.23
irfanview irfanview 3.90
CVE-2012-3585 HIGH

Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview_plugins *
CVE-2012-5904 MEDIUM

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 3.07
irfanview irfanview 2.63
irfanview irfanview 2.52
irfanview irfanview 1.98a
irfanview irfanview 2.00
irfanview irfanview 3.60
irfanview irfanview 2.55
irfanview irfanview 4.30
irfanview irfanview 3.80
irfanview irfanview 3.20
irfanview irfanview 1.70
irfanview irfanview 2.65
irfanview irfanview 3.21
irfanview irfanview 2.92
irfanview irfanview 3.17
irfanview irfanview 2.85
irfanview irfanview 3.36
irfanview irfanview *
irfanview irfanview 3.97
irfanview irfanview 3.92
irfanview irfanview 2.35
irfanview irfanview 2.22
irfanview irfanview 2.83
irfanview irfanview 1.90
irfanview irfanview 2.80
irfanview irfanview 3.50
irfanview irfanview 2.25
irfanview irfanview 1.98
irfanview irfanview 1.80
irfanview irfanview 3.35
irfanview irfanview 3.10
irfanview irfanview 3.30
irfanview irfanview 1.97
irfanview irfanview 2.40
irfanview irfanview 3.91
irfanview irfanview 2.30
irfanview irfanview 3.00
irfanview irfanview 3.70
irfanview irfanview 3.15
irfanview irfanview 2.90
irfanview irfanview 2.12
irfanview irfanview 4.25
irfanview irfanview 3.99
irfanview irfanview 2.50
irfanview irfanview 3.51
irfanview irfanview 2.15
irfanview irfanview 2.37
irfanview irfanview 3.25
irfanview irfanview 2.10
irfanview irfanview 2.98
irfanview irfanview 3.85
irfanview irfanview 2.68
irfanview irfanview 4.27
irfanview irfanview 2.18
irfanview irfanview 2.66
irfanview irfanview 3.05
irfanview irfanview 3.95
irfanview irfanview 4.00
irfanview irfanview 4.28
irfanview irfanview 1.99
irfanview irfanview 1.85
irfanview irfanview 2.32
irfanview irfanview 4.10
irfanview irfanview 1.95
irfanview irfanview 2.20
irfanview irfanview 3.12
irfanview irfanview 4.20
irfanview irfanview 3.75
irfanview irfanview 2.05
irfanview irfanview 3.98
irfanview irfanview 2.60
irfanview irfanview 2.82
irfanview irfanview 3.61
irfanview irfanview 2.07
irfanview irfanview 2.17
irfanview irfanview 2.97
irfanview irfanview 3.02
irfanview irfanview 2.95
irfanview irfanview 3.33
irfanview irfanview 2.27
irfanview irfanview 4.23
irfanview irfanview 3.90
CVE-2013-5351 HIGH

Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.33
irfanview irfanview 3.07
irfanview irfanview 2.63
irfanview irfanview 2.52
irfanview irfanview 1.98a
irfanview irfanview 3.60
irfanview irfanview 2.00
irfanview irfanview 2.55
irfanview irfanview 4.30
irfanview irfanview 3.80
irfanview irfanview 4.32
irfanview irfanview 3.20
irfanview irfanview 1.70
irfanview irfanview 2.65
irfanview irfanview 3.21
irfanview irfanview 3.17
irfanview irfanview 2.92
irfanview irfanview 2.85
irfanview irfanview 3.36
irfanview irfanview *
irfanview irfanview 3.97
irfanview irfanview 3.92
irfanview irfanview 2.35
irfanview irfanview 2.22
irfanview irfanview 2.83
irfanview irfanview 1.90
irfanview irfanview 2.80
irfanview irfanview 2.25
irfanview irfanview 3.50
irfanview irfanview 1.98
irfanview irfanview 1.80
irfanview irfanview 3.35
irfanview irfanview 3.10
irfanview irfanview 2.62
irfanview irfanview 3.30
irfanview irfanview 1.97
irfanview irfanview 2.40
irfanview irfanview 3.70
irfanview irfanview 2.30
irfanview irfanview 3.00
irfanview irfanview 3.91
irfanview irfanview 3.15
irfanview irfanview 2.90
irfanview irfanview 4.25
irfanview irfanview 2.12
irfanview irfanview 3.99
irfanview irfanview 2.50
irfanview irfanview 3.51
irfanview irfanview 4.22
irfanview irfanview 2.15
irfanview irfanview 3.25
irfanview irfanview 2.37
irfanview irfanview 2.10
irfanview irfanview 4.35
irfanview irfanview 2.98
irfanview irfanview 3.85
irfanview irfanview 2.68
irfanview irfanview 4.27
irfanview irfanview 2.18
irfanview irfanview 3.0.7
irfanview irfanview 2.66
irfanview irfanview 3.05
irfanview irfanview 3.95
irfanview irfanview 4.00
irfanview irfanview 4.28
irfanview irfanview 1.99
irfanview irfanview 2.32
irfanview irfanview 1.85
irfanview irfanview 4.10
irfanview irfanview 1.95
irfanview irfanview 2.20
irfanview irfanview 1.75
irfanview irfanview 3.12
irfanview irfanview 4.20
irfanview irfanview 3.75
irfanview irfanview 2.05
irfanview irfanview 3.98
irfanview irfanview 2.60
irfanview irfanview 2.82
irfanview irfanview 3.61
irfanview irfanview 2.07
irfanview irfanview 2.17
irfanview irfanview 2.97
irfanview irfanview 3.33
irfanview irfanview 3.02
irfanview irfanview 2.95
irfanview irfanview 2.27
irfanview irfanview 3.90
irfanview irfanview 4.23
CVE-2013-6932 HIGH

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.25
irfanview irfanview 4.33
irfanview irfanview 4.10
irfanview irfanview 4.30
irfanview irfanview 4.32
irfanview irfanview 4.20
irfanview irfanview 4.35
irfanview irfanview 4.27
irfanview irfanview *
irfanview irfanview 4.00
irfanview irfanview 4.28
irfanview irfanview 4.23
CVE-2017-10729 MEDIUM

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10730 MEDIUM

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d96."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10731 MEDIUM

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d80."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10732 MEDIUM

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10733 MEDIUM

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10734 MEDIUM

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10735 MEDIUM

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-10924 MEDIUM

IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.47
CVE-2017-10925 MEDIUM

IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b3ae."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.47
CVE-2017-10926 MEDIUM

IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.47
CVE-2017-14539 MEDIUM

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-14540 MEDIUM

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x000000000001f23e."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-14578 MEDIUM

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ani file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77130000!RtlpCoalesceFreeBlocks+0x00000000000004b4."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-14693 MEDIUM

IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-15239 MEDIUM

IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000040db4."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15240 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132cef."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15241 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000000929f5."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15242 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x0000000000031abe."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15243 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x00000000000568a4."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15244 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15245 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlGetGlobalState+0x0000000000057b76."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15246 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x000000000001515b."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15247 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000001168a1."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15248 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x0000000000063ca6."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15249 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x00000000000668d6."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15250 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132e19."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15251 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x00000000000e7326."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15252 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x00000000000158cb."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15253 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x000000000007dff2."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15254 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlGetGlobalState+0x000000000007dfa5."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15255 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x00000000001601b0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
CVE-2017-15256 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x0000000000019fc8."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15257 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x000000000009174a."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15258 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000161a9c."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15259 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x000000000011624a."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15260 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000129a59."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15261 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x0000000000057b35."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15262 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x0000000000048d0c."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15263 MEDIUM

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x00000000000166c4."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview pdf 4.43
irfanview irfanview 4.44
CVE-2017-15264 MEDIUM

IrfanView version 4.44 (32bit) allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at image00000000_00400000+0x00000000000236e4."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-15737 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d246f."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15738 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d22d8."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15739 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at CADIMAGE+0x00000000000042d5."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15740 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls Code Flow starting at CADIMAGE+0x000000000033228e."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15741 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Possible Stack Corruption starting at CADIMAGE+0x00000000003d2378."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15742 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d2328."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15743 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADIMAGE+0x00000000003d24a0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15744 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Read Access Violation on Control Flow starting at CADIMAGE+0x00000000003d35a7."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15745 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x000000000002ca2e."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15746 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x00000000003d21b3."

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15747 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x0000700b00260112 called from CADIMAGE+0x00000000003d35ad."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15748 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADIMAGE+0x000000000000613a."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15749 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x00000000000348b9."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15750 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0x0000000000009ae0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15751 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0x0000000000009f39."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15752 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000004d6b0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15753 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x00000000000029c2."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15754 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x0000000000013968."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15755 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at verifier!AVrfpDphFindBusyMemoryNoCheck+0x0000000000000091."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15756 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000004d7c4."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15757 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x00000000000029ba."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15758 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000004d75b."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15759 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001b3f3."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15760 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ce82."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15761 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ecaa."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15762 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001f31b."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15763 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001eca0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15764 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001e6b0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15765 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at CADIMAGE+0x00000000003e9462."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15766 MEDIUM

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001f0a0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview babacad4image 1.3
irfanview irfanview 4.50
CVE-2017-15767 MEDIUM

IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at CADIMAGE+0x00000000003d5b52."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview cadimage 12.0.0.5
irfanview irfanview 4.50
CVE-2017-15768 MEDIUM

IrfanView version 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address controls Branch Selection starting at image000007f7_42060000+0x0000000000094113."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.50
CVE-2017-15769 MEDIUM

IrfanView 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dds file, related to "Read Access Violation starting at FORMATS!ReadBLP_W+0x0000000000001b22."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.50
CVE-2017-2813 MEDIUM

An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 image can cause an integer overflow leading to wrong memory allocation resulting in arbitrary code execution. Vulnerability can be triggered by viewing the image in via the application or by using thumbnailing feature of IrfanView.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-190,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-7721 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx *
CVE-2017-8369 MEDIUM

IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-8370 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different vulnerability than CVE-2017-7721.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview fpx 4.45
irfanview irfanview 4.44
CVE-2017-8766 MEDIUM

IrfanView version 4.44 (32bit) allows remote attackers to execute code via a crafted .mov file, because of a "User Mode Write AV near NULL" issue.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
CVE-2017-9528 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9530 MEDIUM

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000150."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview tools *
irfanview irfanview 4.44
CVE-2017-9531 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX+0x000000000000176c."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9532 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX+0x0000000000001555."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9533 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!DE_Decode+0x0000000000000a9b."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9534 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!GetPlugInInfo+0x0000000000017426."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9535 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!GetPlugInInfo+0x0000000000016e53."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9536 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000000000014eb."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9873 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!GetPlugInInfo+0x0000000000012bf2."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9874 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007822."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9875 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!DE_Decode+0x0000000000000cdb."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9876 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000c995."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9877 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000c998."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9878 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000c99a."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9879 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls subsequent Write Address starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a525."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9880 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007236."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9881 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000000000014e7."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9882 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Block Data Move starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b84f."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9883 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007216."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9884 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000001b6."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9885 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000006a98."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9886 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9887 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX+0x000000000000688d."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9888 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000000000031a0."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9889 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000003714."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9890 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at FPX+0x000000000000153a."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9891 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007053."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9892 MEDIUM

IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview fpx 4.46
CVE-2017-9915 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS plugin 4.50 allows attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "Read Access Violation on Block Data Move starting at ntdll_77df0000!memcpy+0x0000000000000033."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9916 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlFreeHandle+0x00000000000001b6."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview tools 4.50
CVE-2017-9917 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77df0000!RtlFreeHandle+0x0000000000000218."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9918 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!QueryOptionalDelayLoadedAPI+0x0000000000000c42."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9919 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000087."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9920 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResSearchResourceInsideDirectory+0x000000000000029e."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9921 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResGetMappingSize+0x00000000000003cc."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9922 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpCompareResourceNames_U+0x0000000000000062."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2017-9923 MEDIUM

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!EnumResourceTypesInternal+0x0000000000000589."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
irfanview irfanview 4.44
irfanview tools 4.50
CVE-2019-13242 MEDIUM

IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,

Products Affected

Vendor Product Version
irfanview irfanview 4.52
CVE-2019-13243 MEDIUM

IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,

Products Affected

Vendor Product Version
irfanview irfanview 4.52