Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.37% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa." | |
| Modificada | Alta (7.8) | 0.37% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlEnterCriticalSection+0x0000000000000012." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!RtlProcessFlsData+0x00000000000000b0." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Read Access Violation on Control Flow starting at COMCTL32!CToolTipsMgr::s_ToolTipsWndProc+0x0000000000000032." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Stack Buffer Overrun (/GS Exception) starting at ntdll_77df0000!LdrpInitializeNode+0x000000000000015b." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x00000000380a0500 called from ntdll_77df0000!LdrxCallInitRoutine+0x0000000000000016." | |
| Modificada | Alta (7.8) | 0.40% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121." | |
| Modificada | Alta (7.8) | 0.37% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlRbInsertNodeEx+0x000000000000002d." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000000c1b541c called from xnview+0x00000000003826ec." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000002f32332f called from KERNELBASE!CompareStringW+0x0000000000000082." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000002e6." | |
| Modificada | Alta (7.8) | 0.36% | — | Xnview | 5/7/2017 | 17/6/2026 | XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at msvcrt!_VEC_memzero+0x000000000000006a." | |
| Modificada | Alta (9.3) | 9.9% | 💥 Exploit | Xnview | 9/7/2014 | 16/6/2026 | Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file. | |
| Modificada | Alta (9.3) | 3.5% | — | Xnview | 18/3/2014 | 16/6/2026 | Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Xnview | 9/8/2013 | 16/6/2026 | Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file. | |
| Modificada | Media (6.8) | 7.4% | 💥 Exploit | Xnview | 17/7/2012 | 16/6/2026 | Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image. | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Xnview | 17/7/2012 | 16/6/2026 | Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT image. | |
| Modificada | Media (6.8) | 8.3% | 💥 Exploit | Xnview | 17/7/2012 | 16/6/2026 | Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL. | |
| Modificada | Alta (9.3) | 3.7% | — | Xnview | 9/5/2012 | 16/6/2026 | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684. | |
| Modificada | Alta (9.3) | 3.7% | — | Xnview | 9/5/2012 | 16/6/2026 | Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685. | |
| Modificada | Media (6.8) | 2.6% | — | Xnview | 13/2/2012 | 16/6/2026 | Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Media (6.9) | 0.34% | — | Xnview | 11/7/2011 | 16/6/2026 | Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Xnview | 16/6/2010 | 16/6/2026 | Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that contains a malformed Encoding field. | |
| Modificada | Alta (9.3) | 4.6% | — | Xnview | 15/3/2010 | 16/6/2026 | Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 16% | 💥 Exploit | Pagesperso-orange GFL SDKPagesperso-orange NconvertPagesperso-orange Xnview | 24/6/2008 | 16/6/2026 | Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file. |