Out-Of-Bounds Read Vulnerability in IrfanView CADImage Plugin
CVE-2025-7265
7.8HIGH
What is CVE-2025-7265?
The IrfanView CADImage Plugin contains a vulnerability in the parsing of CGM files, leading to an Out-Of-Bounds Read condition. This flaw arises from inadequate validation of user-supplied data, enabling attackers to potentially read beyond allocated buffers. Successful exploitation requires user interaction, requiring the targeted user to access a malicious web page or open a specially crafted file, which could allow an attacker to execute arbitrary code within the context of the affected process.
Affected Version(s)
IrfanView 4.70.0.0