CVE-2012-4988: Xnview

High severity, CVSS 9.3. EPSS: 9.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

Affected products

  • Xnview Xnview: version 1.99 only; version 1.99.1 only

Published 2014-07-09. Last modified 2026-06-16.