CVE-2013-5351
https://notcve.org/view.php?id=CVE-2013-5351
Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file. Desbordamiento de buffer basado en pila en IrfanView anterior a 4.37 permite a atacantes remotos ejecutar código arbitrario a través del flujo de código LZW en un archivo GIF. • http://osvdb.org/101065 http://secunia.com/advisories/54959 http://secunia.com/secunia_research/2013-13 http://www.irfanview.com/main_history.htm http://www.securityfocus.com/bid/64388 https://exchange.xforce.ibmcloud.com/vulnerabilities/89808 https://exchange.xforce.ibmcloud.com/vulnerabilities/89820 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2013-6932
https://notcve.org/view.php?id=CVE-2013-6932
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window. Desbordamiento de búfer en IrfanView anterior a 4.37 cuando se utiliza un nombre de directorio de caracteres multibyte, que permite a atacantes remotos ejecutar código arbitrario mediante un archivo manipulado el cual se maneja incorrectamente por la funcionalidad de información de herramientas en miniatura ofrecen en la ventana Miniaturas. • http://jvn.jp/en/jp/JVN63194482/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2013-000120 http://www.irfanview.com/main_history.htm • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-5904
https://notcve.org/view.php?id=CVE-2012-5904
Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image. Una vulnerabilidad de desbordamiento de búfer basado en memoria dinámica en IrfanView antes de v4.33 permite a atacantes remotos ejecutar código de su elección a través de un archivo de mapa de bits comprimido RLE modificado como si fuera una imagen DIB, RLE o BMP. • http://osvdb.org/80716 http://secunia.com/advisories/47333 http://www.irfanview.com/history_old.htm http://www.securityfocus.com/bid/52806 https://exchange.xforce.ibmcloud.com/vulnerabilities/74452 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-0278 – IrfanView FlashPix PlugIn - Decompression Heap Overflow
https://notcve.org/view.php?id=CVE-2012-0278
Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression. Desbordamiento de búfer basado en memoria dinámica en FlashPix PlugIn antes de v4.3.4.0 para IrfanView, podría permitir a atacantes remotos ejecutar código arbitrario mediante un archivo .FPX que contiene una imagen FlashPix manipulada que no se maneja adecuadamente durante la descompresión. • https://www.exploit-db.com/exploits/18739 http://secunia.com/advisories/48772 http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=41&Itemid=41 http://www.securityfocus.com/bid/53009 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-0897 – IrfanView JPEG2000 4.3.2.0 - jp2 Stack Buffer Overflow
https://notcve.org/view.php?id=CVE-2012-0897
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. Desbordamiento de búfer basado en pila en el complemento JPEG2000 para IrfanView PlugIns, permite a atacantes remotos ejecutar código de su elección a través de un archivo JPEG2000 (JP2) con un marcador de segmento Quantization Default (QCD) manipulado. Printer virtualization under VMware Workstation involves a vprintproxy.exe process launched by vmware-vmx.exe on the Host. It will receive and process EMFSPOOL files sent by a Guest on its COM1 port, if a virtual printer has been added to the VM hardware (default). Several vulnerabilities in this component allow an unprivileged Guest user to execute code on the Host. • https://www.exploit-db.com/exploits/19519 http://osvdb.org/78333 http://secunia.com/advisories/47360 http://www.irfanview.com/history_old.htm http://www.securityfocus.com/bid/51426 http://www.securitytracker.com/id/1032529 http://www.securitytracker.com/id/1032530 https://exchange.xforce.ibmcloud.com/vulnerabilities/72398 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •