7.6
CVSSv2

CVE-2008-1461

Published: 24/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in XnView 1.92.1 allows user-assisted remote malicious users to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.

Vulnerable Product Search on Vulmon Subscribe to Product

xnview xnview 1.92.1

Exploits

source: wwwsecurityfocuscom/bid/28259/info XnView is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer Attackers may exploit this issue only if XnView is configured as a handler for other applications, so that it can be passed m ...