CVE-2007-4343
https://notcve.org/view.php?id=CVE-2007-4343
Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file. Desbordamiento de búfer basado en pila en IrfanView 3.99 y 4.00 permite a atacantes remotos con la intervención del usuario ejecutar código de su elección a través de archivos de la paleta (.pla) manipulados. • http://secunia.com/advisories/26619 http://secunia.com/secunia_research/2007-71/advisory http://www.irfanview.com/main_history.htm http://www.securityfocus.com/bid/26089 http://www.vupen.com/english/advisories/2007/3528 https://exchange.xforce.ibmcloud.com/vulnerabilities/37222 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2007-2363 – IrfanView 4.00 - '.iff' Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-2363
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. Desbordamiento de búfer en el IrfanView 4.00 y versiones anteriores permite a atacantes remotos con la intervención del usuario ejecutar código de su elección mediante un fichero .IFF manipulado. • https://www.exploit-db.com/exploits/3811 https://www.exploit-db.com/exploits/6188 http://osvdb.org/35463 http://secunia.com/advisories/25052 http://www.securityfocus.com/bid/23692 http://www.vupen.com/english/advisories/2007/1575 https://exchange.xforce.ibmcloud.com/vulnerabilities/33946 •
CVE-2007-1948 – IrfanView 3.99 - Multiple .BMP Denial of Service Vulnerabilities
https://notcve.org/view.php?id=CVE-2007-1948
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp. Desbordamiento de búfer en IrfanView 3.99 permite a atacantes dependiendo del contexto provocar denegación de servicio y posiblemente ejecutar código de su elección a través de los comandos (1) xoffset o (2) yoffset RLE, o (3) la codificación en bloques non-RLE en un imagen BMP manipulada, como se demostró con rle8of3.bmp y rle8of4.bmp. • https://www.exploit-db.com/exploits/29819 http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html http://osvdb.org/41554 http://securityreason.com/securityalert/2558 http://www.securityfocus.com/archive/1/464726/100/0/threaded http://www.vupen.com/english/advisories/2007/1284 •
CVE-2007-1867 – IrfanView 3.99 - '.ani' Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-1867
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. Desbordamiento de búfer en IrfanView 3.99 permite a atacantes remotos ejecutar código de su elección mediante un fichero de cursor animado (ANI) manipulado. • https://www.exploit-db.com/exploits/3692 https://www.exploit-db.com/exploits/3648 http://secunia.com/advisories/24725 http://www.securityfocus.com/bid/23262 http://www.vupen.com/english/advisories/2007/1210 https://exchange.xforce.ibmcloud.com/vulnerabilities/33386 •
CVE-2007-1245
https://notcve.org/view.php?id=CVE-2007-1245
IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file. IrfanView 3.99 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) mediante un fichero WMF mal formado. • http://osvdb.org/34487 http://securityvulns.com/Qdocument120.html http://securityvulns.com/news/IrfanView/WMF/DoS.html http://www.securityfocus.com/archive/1/461373/100/0/threaded • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •