Xnview develops a suite of image-viewing and batch-conversion tools including XNView, NConvert, and XNView MP that span both legacy and modern platforms, and while the product line itself is narrowly focused, the vendor appears prominently in the vulnerability landscape. The vendor's disclosures cluster decisively around memory-safety issues: buffer-overflow conditions, improper bounds checking, and heap-based write vulnerabilities that are characteristic of image-parsing codebases handling untrusted file formats. These weakness classes reflect the attack surface inherent to processing complex image headers and codec data, where malformed or specially crafted files can trigger out-of-bounds access. Defenders should treat image-processing workflows as a vector for exploitation and prioritize updates to this vendor's tools, particularly in environments that batch-process or auto-convert untrusted image files; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xnview over time
Signals from CVEs in this vendor scope (174 CVEs).
174 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4988HIGH Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a c | Jul 9, 2014 | 9.3 | 43 | NO | YES |
CVE-2013-2577HIGH Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file. | Aug 9, 2013 | 9.3 | 43 | NO | YES |
CVE-2010-1932HIGH Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that conta | Jun 16, 2010 | 9.3 | 41 | NO | YES |
CVE-2012-0282MEDIUM Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLef | Jul 17, 2012 | 6.8 | 35 | NO | YES |
CVE-2012-0277MEDIUM Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT imag | Jul 17, 2012 | 6.8 | 34 | NO | YES |
CVE-2012-0276MEDIUM Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI | Jul 17, 2012 | 6.8 | 34 | NO | YES |
CVE-2008-1461HIGH Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether ther | Mar 24, 2008 | 7.6 | 33 | NO | YES |
CVE-2012-0684HIGH Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability | May 9, 2012 | 9.3 | 29 | NO | NO |
CVE-2012-0685HIGH Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability | May 9, 2012 | 9.3 | 28 | NO | NO |
CVE-2023-52174CRITICAL XnView Classic before 2.51.3 on Windows has a Write Access Violation at xnview.exe+0x3125D6. | Dec 29, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (174 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xnview.
Media articles that mention a CVE ID that affects a product developed by Xnview — matched by CVE ID, not by vendor name.