CVE-2012-5904: Irfanview

Medium severity, CVSS 6.8. EPSS: 5.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

Affected products

  • Irfanview Irfanview: up to and including 4.32; version 1.70 only; version 1.80 only; version 1.85 only; version 1.90 only; version 1.95 only; …

Published 2012-11-17. Last modified 2026-06-16.