Vulnerabilidades em IrfanView

184 resultados
Análise Vexday

O IrfanView acumula 183 CVEs catalogadas, volume considerável para um visualizador de imagens, com CWE-119 (falhas de gerenciamento de memória, como buffer overflow) como categoria dominante — padrão típico de aplicações que processam múltiplos formatos de arquivo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, sem nenhum registro no KEV até o momento, e a ausência de PoCs públicas conhecidas reduz a exposição imediata. A CVE mais relevante no contexto atual é CVE-2013-3944, com score EPSS de 0,275, indicando probabilidade não trivial de exploração apesar da sua antiguidade — o que sugere que vulnerabilidades históricas nessa base de código merecem atenção em ambientes onde o software ainda está em uso. A inexistência de novas CVEs nos últimos 90 dias pode refletir menor atividade de pesquisa recente, mas não deve ser interpretada como ausência de risco residual na superfície de ataque legada.

CVE-2013-3944Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via EPSS 27.5%CVE-2013-3946Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via aEPSS 2.5%CVE-2013-3945The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.EPSS 2.1%CVE-2017-2813HIGHAn exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 iEPSS 1.7%CVE-2024-6817HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-6815HIGHIrfanView RLE File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-6816HIGHIrfanView PSP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-6811HIGHIrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6812HIGHIrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6820HIGHIrfanView AWD File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6819HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6818HIGHIrfanView PSP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6821HIGHIrfanView CIN File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-6822HIGHIrfanView CIN File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5875HIGHIrfanView SHP File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5877HIGHIrfanView PIC File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5874HIGHIrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5876HIGHIrfanView PSP File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-11515HIGHIrfanView JPM File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-11517HIGHIrfanView JPM File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%