← Back

Irfanview

irfanview

290 CVEs • 13 products

Products (13)

Click to collapse
Toggle
Irfanview
irfanview
Fpx
fpx
Pdf
pdf
Babacad4image
babacad4image
Cadimage
cadimage
Tools
tools
Formats
formats
B3d
b3d
Exr
exr
Wpg
wpg
Wsq
wsq

CVEs (290)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starti...Show more
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."Show less
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x0...Show more
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x000000000000001d."Show less
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starti...Show more
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."Show less
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starti...Show more
IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."Show less
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d80."
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d96."
1Irfanview
1Irfanview
May 13, 2026
Jul 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000...Show more
IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."Show less
1Irfanview
1Irfanview
May 13, 2026
Jun 21, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 image can cause an integer overflow leading to wrong memory allocation resulting...Show more
An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 image can cause an integer overflow leading to wrong memory allocation resulting in arbitrary code execution. Vulnerability can be triggered by viewing the image in via the application or by using thumbnailing feature of IrfanView.Show less
1Irfanview
2Fpx
Irfanview
May 13, 2026
Apr 30, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.
1Irfanview
1Irfanview
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.
1Irfanview
1Irfanview
Apr 29, 2026
Dec 28, 2013
N/A· v4
N/A· v3
7.6 HIGH· v2
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail...Show more
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.Show less
1Irfanview
1Irfanview
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.
1Irfanview
1Flashpix Plugin
Apr 29, 2026
Nov 2, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via...Show more
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.Show less
1Irfanview
1Irfanview
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
1Irfanview
1Irfanview Plugins
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.
1Irfanview
1Flashpix Plugin
Apr 29, 2026
Apr 18, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled durin...Show more
Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.Show less
1Irfanview
1Irfanview
Apr 29, 2026
Jan 20, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
1Irfanview
1Irfanview
Apr 29, 2026
May 14, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.
1Irfanview
1Irfanview
Apr 29, 2026
May 14, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."Show less
1Irfanview
1Irfanview
Apr 23, 2026
Jun 18, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.