Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 7.7% | 💥 Exploit | Irfanview Plugins | 5/7/2012 | 16/6/2026 | Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Irfanview Flashpix Plugin | 18/4/2012 | 16/6/2026 | Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression. | |
| Modificada | Media (6.8) | 52% | 💥 Exploit | Irfanview | 20/1/2012 | 16/6/2026 | Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Media (5) | 4.5% | — | Irfanview | 14/5/2010 | 16/6/2026 | Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression. | |
| Modificada | Media (5) | 3.7% | — | Irfanview | 14/5/2010 | 16/6/2026 | IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a… | |
| Modificada | Media (6.8) | 2.5% | — | Irfanview | 18/6/2009 | 16/6/2026 | Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 4.8% | — | Irfanview Formats | 9/4/2009 | 16/6/2026 | Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 8.7% | 💥 Exploit | Irfanview | 30/1/2008 | 16/6/2026 | fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5.1) | 2.9% | — | Irfanview | 16/10/2007 | 16/6/2026 | Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file. | |
| Modificada | Alta (8.5) | 8.9% | 💥 Exploit | Irfanview | 30/4/2007 | 16/6/2026 | Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. | |
| Modificada | Alta (9.3) | 8.3% | 💥 Exploit | Irfanview | 11/4/2007 | 16/6/2026 | Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp. | |
| Modificada | Alta (10) | 7.9% | 💥 Exploit | Irfanview | 4/4/2007 | 16/6/2026 | Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. | |
| Modificada | Media (4.3) | 1.2% | — | Irfanview | 3/3/2007 | 16/6/2026 | IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file. | |
| Modificada | Baja (2.6) | 2.7% | 💥 Exploit | Irfanview | 26/8/2006 | 16/6/2026 | IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow. | |
| Modificada | Baja (2.6) | 1.3% | — | Irfanview | 18/8/2006 | 16/6/2026 | IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Irfanview | 9/11/1999 | 16/6/2026 | Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header. |