CVE-2012-0025: Irfanview Flashpix Plugin
Medium severity, CVSS 6.8. EPSS: 6.4% chance of exploitation in the next 30 days.
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.
Affected products
- Irfanview Flashpix Plugin: version 4.2.2.0 only
Published 2012-11-02. Last modified 2026-06-16.