6.8
CVSSv2

CVE-2012-0276

Published: 17/07/2012 Updated: 18/07/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple heap-based buffer overflows in XnView prior to 1.99 allow remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xnview xnview

Exploits

##################################################################################### Application: XnView TIFF Image Processing Heap Overflow Platforms: Windows Secunia: SA48666 {PRL}: 2012-16 Author: Francis Provencher (Protek Research Lab's) Website: wwwprotekresearchlabcom/ Twitter: @ProtekResearch ############ ...
##################################################################################### Application: XnView TIFF Image Processing Heap Overflow Platforms: Windows Secunia: SA48666 {PRL}: 2012-15 Author: Francis Provencher (Protek Research Lab's) Website: wwwprotekresearchlabcom/ Twitter: @ProtekResearch ########## ...