← العودة للجدول
CVE-2013-3941
CVE-2013-3941 — Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code
📅 2020-01-02
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 9.8

📋 الوصف الكامل

Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.

💻 الأنظمة المتأثرة

Xjp2.dll in XnView before

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2013-3941

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2013-3941 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←