Remote Denial of Service Vulnerability in XnView MP on Windows
CVE-2019-9962

7.8HIGH

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
24 March 2019

What is CVE-2019-9962?

XnView MP 0.93.1 on Windows is susceptible to a denial of service due to improperly handled crafted files. Attackers can exploit this vulnerability to trigger application crashes by leveraging issues related to the memory copying function in the VCRUNTIME140 library, potentially resulting in other unspecified impacts.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.