← All CVEs

CVE-2008-1461

high · 7.6

Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.

7.6
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2008-03-24
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
xnviewxnview1.92.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-1461