Out-of-Bounds Write Vulnerability in FastStone Image Viewer by FastStone Soft
CVE-2026-101203

5.3MEDIUM

Key Information:

Vendor

Faststone

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101203?

A vulnerability exists in FastStone Image Viewer, affecting versions up to 8.3, where the 1bpp RLE Decoder has an unknown function that can be exploited to perform an out-of-bounds write. This weakness allows attackers to manipulate the software, potentially leading to unauthorized access or system compromise, and can be triggered remotely. Despite early notification to the vendor regarding this issue, no response has been recorded.

Affected Version(s)

Image Viewer 8.0

Image Viewer 8.1

Image Viewer 8.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jonzab (VulDB User)
VulDB CNA Team
.