CVE-2012-0685: Xnview

High severity, CVSS 9.3. EPSS: 3.7% chance of exploitation in the next 30 days.

Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684.

Affected products

  • Xnview Xnview: up to and including 1.98.4; version 1.0 only; version 1.01 only; version 1.02 only; version 1.03 only; version 1.04 only; …

Published 2012-05-09. Last modified 2026-06-16.