Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Irfanview

First CVE: Nov 9, 1999Active for: 27 yearsTotal CVEs: 381
47.0
VTI Score
High

Irfanview is a widely deployed image viewer and multimedia software suite with a modest product line that punches above its typical footprint in the vulnerability landscape, driven largely by its desktop ubiquity and long maintenance history. The vendor's disclosures cluster heavily around memory-safety weaknesses—buffer overflows, out-of-bounds reads and writes, and improper memory-bounds checking—reflecting the native-code image and document parsing demands of viewer and media-handling applications like Irfanview, FPX, PDF, and related tools. These classes of flaws are inherent to image format handling and are characteristic of products that consume untrusted binary input across many legacy and contemporary file formats. Defenders should treat Irfanview updates as important given its prevalence on end-user systems and the potential for remote exploitation through image attachments and web downloads; live severity, exploitation activity, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
381
Total CVEs
More Total CVEs than 100% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Irfanview over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 9, 1999
26 years ago
Most Recent CVE
Jul 21, 2025
368 days ago

Products(13 total)

Top CVEs

Signals from CVEs in this vendor scope (381 CVEs).

381 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-0897MEDIUM
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quant
Jan 20, 20126.870NOYES
CVE-2021-27224HIGH
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary
Feb 17, 20217.543NONO
CVE-2012-3585HIGH
Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code
Jul 5, 20129.342NOYES
CVE-2012-0278HIGH
Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix
Apr 18, 20129.342NOYES
CVE-2007-1948HIGH
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command
Apr 11, 20079.339NOYES
CVE-2007-1867HIGH
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
Apr 4, 200710.038NOYES
CVE-2008-0493HIGH
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOT
Jan 30, 20089.336NOYES
CVE-2012-0025MEDIUM
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers
Nov 2, 20126.834NOYES
CVE-2007-2363HIGH
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
Apr 30, 20078.534NOYES
CVE-2021-27362CRITICAL
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to exe
Feb 17, 20219.831NONO
View all 381 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products381 CVEs
92%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local352 (92.4%)
Network8 (2.1%)
Unknown21 (5.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low360 (94.5%)
High0 (0.0%)
Unknown21 (5.5%)
User Interaction
None26 (6.8%)
Unknown21 (5.5%)
Required334 (87.7%)
Privileges Required
Low20 (5.2%)
High0 (0.0%)
None340 (89.2%)
Unknown21 (5.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (381 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Irfanview.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Irfanview — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Irfanview's Products

View all 5 CNAs →

Top CWEs