Skip to main content

Vendor archive

xnview CVEs

Beta · best-effort

174 CVEs tagged to vendor xnview12 Critical, 152 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2026-30007

Published Mar 23, 2026

XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-30006

Published Mar 23, 2026

XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-11950

Published Dec 12, 2024

XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22532

Published Feb 28, 2024

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46587

Published Oct 27, 2023

Buffer Overflow vulnerability in XnView Classic v.2.51.5 allows a local attacker to execute arbitrary code via a crafted TIF file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43251

Published Oct 19, 2023

XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43252

Published Oct 19, 2023

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43250

Published Oct 18, 2023

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28835

Published Aug 11, 2023

Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28427

Published Aug 11, 2023

Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23887

Published Nov 10, 2021

XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation st…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23886

Published Nov 10, 2021

XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV star…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3941

Published Jan 2, 2020

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2)…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3939

Published Jan 2, 2020

xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE str…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3937

Published Jan 2, 2020

Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3247

Published Jan 2, 2020

Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3246

Published Jan 2, 2020

Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17262

Published Oct 8, 2019

XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17261

Published Oct 8, 2019

XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13262

Published Jul 4, 2019

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13261

Published Jul 4, 2019

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 174 CVEsPage 1 of 7