Описание
Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:xnview:xnview:2.13:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.09951
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-189
Связанные уязвимости
github
больше 3 лет назад
Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow.
EPSS
Процентиль: 93%
0.09951
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-189