CVE-2011-5233: Irfanview

Medium severity, CVSS 4.3. EPSS: 9.3% chance of exploitation in the next 30 days.

Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.

Affected products

  • Irfanview Irfanview: up to and including 4.30; version 3.90 only; version 3.91 only; version 3.92 only; version 3.95 only; version 3.97 only; …

Published 2012-10-25. Last modified 2026-06-16.