CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-10739

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000000c1b541c called from xnview+0x00000000003826ec."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10740

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlRbInsertNodeEx+0x000000000000002d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10741

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10742

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x00000000380a0500 called from ntdll_77df0000!LdrxCallInitRoutine+0x0000000000000016."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10743

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!LdrpInitializeNode+0x000000000000015b."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10746

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10747

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10748

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10749

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10750

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV near NULL starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10753

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByMapping+0x0000000000000046."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10754

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10755

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpInitializeThread+0x000000000000010b."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10756

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpRemoveUCRBlock+0x0000000000000046."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10757

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000001b6."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10759

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpInsertDependencyRecord+0x0000000000000039."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10760

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at COMCTL32!SetStatusText+0x0000000000000029."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10761

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10762

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x000000000000042f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10763

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByHandle+0x0000000000000031."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10765

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10766

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at GDI32!ScriptStringAnalyse+0x00000000000001c8."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10767

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!StateObjectListFind+0x0000000000000005."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10768

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpInsertFreeBlock+0x00000000000001ca."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10769

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!memcmp+0x0000000000000018" (without RPC initialization).

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10772

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!memcmp+0x0000000000000018" (with RPC initialization).

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10773

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at MSCTF!_CtfImeCreateThreadMgr+0x00000000000000a8."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10774

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!FindSortHashNode+0x0000000000000040."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10775

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to a "Read Access Violation starting at GDI32!ScriptGetCMapWithSurrogate+0x00000000000001cb."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10776

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to a "Read Access Violation starting at ntdll_77df0000!LdrShutdownProcess+0x0000000000000130."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10778

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000233125."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10779

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000013a20."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10780

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000372b4a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10781

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpFindLoadedDllByName+0x00000000000000a5."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10782

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10783

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10925

    Last Modified: 20 Apr 2025

    IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b3ae."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10926

    Last Modified: 20 Apr 2025

    IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-7894

    Last Modified: 20 Apr 2025

    WinDjView 2.1 might allow user-assisted attackers to execute code via a crafted .djvu file, because of a "User Mode Write AV near NULL" in WinDjView.exe. One threat model is a victim who obtains an untrusted .djvu file from a remote location and issues several user-defined commands.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8370

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different vulnerability than CVE-2017-7721.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8381

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled during the opening of a directory in "Browser" mode, because of a "User Mode Write AV near NULL" in XnView.exe.

    Published: 5 Jul 2017
    5.5
    Medium

    CVE-2017-8387

    Last Modified: 20 Apr 2025

    STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands including Ctrl-+ commands.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8766

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) allows remote attackers to execute code via a crafted .mov file, because of a "User Mode Write AV near NULL" issue.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8785

    Last Modified: 20 Apr 2025

    FastStone Image Viewer 6.2 has a "Data from Faulting Address may be used as a return value" issue. This issue can be triggered by a malformed JPEG 2000 file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8803

    Last Modified: 20 Apr 2025

    Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9530

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000150."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9531

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX+0x000000000000176c."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9532

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX+0x0000000000001555."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9533

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!DE_Decode+0x0000000000000a9b."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9534

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!GetPlugInInfo+0x0000000000017426."

    Published: 5 Jul 2017