vulnerability

XnSoft XnView: CVE-2013-3939: XnView RGB File Handling Heap Based Buffer Overflow Vulnerability

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jan 2, 2020
Added
Jan 22, 2020
Modified
Aug 11, 2025

Description

xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.

Solution

xnsoft-xnview-upgrade-2_13
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.