CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-9893

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000012548."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9894

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000029272."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9878

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000c99a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9873

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!GetPlugInInfo+0x0000000000012bf2."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9875

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!DE_Decode+0x0000000000000cdb."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9877

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000c998."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9881

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000000000014e7."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9882

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Block Data Move starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b84f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9883

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007216."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9885

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000006a98."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9888

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000000000031a0."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9889

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000003714."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9890

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at FPX+0x000000000000153a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9891

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007053."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9892

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9897

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x000000000000dcab."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9898

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004cbb."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9899

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e388."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9900

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e385."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9901

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls subsequent Write Address starting at Xfpx!gffGetFormatInfo+0x000000000002bfd5."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9902

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x0000000000020e91."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9907

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Possible Stack Corruption starting at Xfpx!gffGetFormatInfo+0x0000000000022e1f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9909

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlAddAccessAllowedAce+0x000000000000027a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9910

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to an "Error Code (0xc000041d) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9913

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!TpAllocCleanupGroup+0x00000000000003d7."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9914

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .bie file, related to a "Read Access Violation on Block Data Move starting at Xjbig+0x000000000000121b."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9915

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS plugin 4.50 allows attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "Read Access Violation on Block Data Move starting at ntdll_77df0000!memcpy+0x0000000000000033."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9916

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlFreeHandle+0x00000000000001b6."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9917

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77df0000!RtlFreeHandle+0x0000000000000218."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9920

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResSearchResourceInsideDirectory+0x000000000000029e."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9921

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResGetMappingSize+0x00000000000003cc."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9922

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpCompareResourceNames_U+0x0000000000000062."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9923

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!EnumResourceTypesInternal+0x0000000000000589."

    Published: 5 Jul 2017
    8.8
    High

    CVE-2017-9924

    Last Modified: 20 Apr 2025

    In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV starting at image00000000_00400000+0x000000000001b72a."

    Published: 5 Jul 2017
    8.8
    High

    CVE-2017-9927

    Last Modified: 20 Apr 2025

    In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to a "Read Access Violation starting at image00000000_00400000+0x000000000001b5fe."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10924

    Last Modified: 20 Apr 2025

    IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529."

    Published: 5 Jul 2017
    7.3
    High

    CVE-2017-10725

    Last Modified: 20 Apr 2025

    Winamp 5.666 Build 3516(x86) allows attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address controls Code Flow starting at in_flv!winampGetInModule2+0x00000000000009a8."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10745

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!RtlProcessFlsData+0x00000000000000b0."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10752

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10771

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCreateSplitBlock+0x0000000000000510."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8282

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mov file that is mishandled during the opening of a directory in "Browser" mode, because of a "User Mode Write AV near NULL" in XnView.exe.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8368

    Last Modified: 20 Apr 2025

    Sublime Text 3 Build 3126 allows user-assisted attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mkv file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands, as demonstrated by Ctrl-A, Delete, and Ctrl-Z.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8781

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted JPEG 2000 file that is mishandled during the opening of a directory in "Browser" mode, because of a "Stack Buffer Overrun" issue.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9987

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120553.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9988

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120554.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9989

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120555.

    Published: 5 Jul 2017
    7.5
    High

    CVE-2017-1264

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.

    Published: 5 Jul 2017
    4.3
    Medium

    CVE-2016-9700

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2017-1096

    Last Modified: 20 Apr 2025

    IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656.

    Published: 5 Jul 2017
    2.5
    Low

    CVE-2017-1144

    Last Modified: 20 Apr 2025

    IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033.

    Published: 5 Jul 2017