Description
Buffer Overflow vulnerability in IrfanView 32bit v.4.66 allows a local attacker to cause a denial of service via a crafted file. Affected component is IrfanView 32bit 4.66 with plugin formats.dll.
References (4)
Core 4
Core References
Various Sources
https://www.fosshub.com/IrfanView.html?dwl=iview466_setup.exe
Various Sources
https://mediaside.net/irfanview-italia/2024/04/12/4-67-data-di-rilascio-5-aprile-2024/
Various Sources
https://www.fosshub.com/IrfanView.html?dwl=iview466_plugins.zip
Scores
CVSS v3
5.5
EPSS
0.0008
EPSS Percentile
22.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-120
Status
published
Published
Oct 21, 2024
Tracked Since
Feb 18, 2026