CVE-2026-107125: Xnview Classic
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.
Affected products
- Xnview Classic: version 2.52.5 only
Published 2026-10-07. Last modified 2026-10-07.