CVE-2012-0282: Xnview

Medium severity, CVSS 6.8. EPSS: 7.5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image.

Affected products

  • Xnview Xnview: up to and including 1.98.8

Published 2012-07-17. Last modified 2026-06-16.