CVE-2013-3938: Xnview

High severity, CVSS 9.3. EPSS: 3.5% chance of exploitation in the next 30 days.

Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow.

Affected products

  • Xnview Xnview: version 2.13 only

Published 2014-03-18. Last modified 2026-06-16.