Buffer Overflow Vulnerability in XNView by XnView Software
CVE-2021-28835

7.8HIGH

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
11 August 2023

What is CVE-2021-28835?

A buffer overflow vulnerability exists in XNView versions before 2.50, enabling local attackers to execute arbitrary code by using specially crafted GEM bitmap files. This flaw can lead to severe security risks if exploited, allowing attackers to potentially compromise the integrity and confidentiality of the system running the affected software.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.