Irfanview is a widely deployed image viewer and multimedia software suite with a modest product line that punches above its typical footprint in the vulnerability landscape, driven largely by its desktop ubiquity and long maintenance history. The vendor's disclosures cluster heavily around memory-safety weaknesses—buffer overflows, out-of-bounds reads and writes, and improper memory-bounds checking—reflecting the native-code image and document parsing demands of viewer and media-handling applications like Irfanview, FPX, PDF, and related tools. These classes of flaws are inherent to image format handling and are characteristic of products that consume untrusted binary input across many legacy and contemporary file formats. Defenders should treat Irfanview updates as important given its prevalence on end-user systems and the potential for remote exploitation through image attachments and web downloads; live severity, exploitation activity, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Irfanview over time
Signals from CVEs in this vendor scope (381 CVEs).
381 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0897MEDIUM Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quant | Jan 20, 2012 | 6.8 | 70 | NO | YES |
CVE-2021-27224HIGH The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary | Feb 17, 2021 | 7.5 | 43 | NO | NO |
CVE-2012-3585HIGH Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code | Jul 5, 2012 | 9.3 | 42 | NO | YES |
CVE-2012-0278HIGH Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix | Apr 18, 2012 | 9.3 | 42 | NO | YES |
CVE-2007-1948HIGH Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command | Apr 11, 2007 | 9.3 | 39 | NO | YES |
CVE-2007-1867HIGH Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file. | Apr 4, 2007 | 10.0 | 38 | NO | YES |
CVE-2008-0493HIGH fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOT | Jan 30, 2008 | 9.3 | 36 | NO | YES |
CVE-2012-0025MEDIUM Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers | Nov 2, 2012 | 6.8 | 34 | NO | YES |
CVE-2007-2363HIGH Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file. | Apr 30, 2007 | 8.5 | 34 | NO | YES |
CVE-2021-27362CRITICAL The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133, which might allow remote attackers to exe | Feb 17, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (381 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Irfanview.
Media articles that mention a CVE ID that affects a product developed by Irfanview — matched by CVE ID, not by vendor name.