IrfanView 3.98 (with plugins) allows remote malicious users to cause a denial of service (application crash) via a crafted CUR image file.
irfanview irfanview 3.98