CVE-2012-0278: Irfanview Flashpix Plugin

High severity, CVSS 9.3. EPSS: 10.1% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.

Affected products

  • Irfanview Flashpix Plugin: up to and including 4.33; version 4.32 only

Published 2012-04-18. Last modified 2026-06-16.