Heap-based Buffer Overflow in XnView Classic Parsing FLI Files
CVE-2026-107125

5.3MEDIUM

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107125?

A vulnerability has been identified in XnView Classic version 2.52.5, specifically within the FLI File Parser component. The issue arises from a manipulation of the argument 'starting_line', leading to a heap-based buffer overflow that could be exploited remotely. To mitigate this risk, users are strongly urged to upgrade to version 2.52.6 or later, as this addresses the vulnerability effectively.

Affected Version(s)

Classic 2.52.5

Classic 2.52.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jonzab (VulDB User)
.