CVE-2013-2577
high · 9.3Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
9.3
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2013-08-09
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| xnview | xnview | <= 2.03 |
| xnview | xnview | 1.0 |
| xnview | xnview | 1.01 |
| xnview | xnview | 1.02 |
| xnview | xnview | 1.03 |
| xnview | xnview | 1.04 |
| xnview | xnview | 1.05 |
| xnview | xnview | 1.05 |
| xnview | xnview | 1.05 |
| xnview | xnview | 1.06 |
| xnview | xnview | 1.07 |
| xnview | xnview | 1.08 |
| xnview | xnview | 1.09 |
| xnview | xnview | 1.10 |
| xnview | xnview | 1.11 |
| xnview | xnview | 1.12 |
| xnview | xnview | 1.13 |
| xnview | xnview | 1.14 |
| xnview | xnview | 1.15 |
| xnview | xnview | 1.16 |
| xnview | xnview | 1.17 |
| xnview | xnview | 1.17 |
| xnview | xnview | 1.18 |
| xnview | xnview | 1.18.1 |
| xnview | xnview | 1.19 |
| xnview | xnview | 1.20 |
| xnview | xnview | 1.21 |
| xnview | xnview | 1.22 |
| xnview | xnview | 1.23 |
| xnview | xnview | 1.24 |
| xnview | xnview | 1.25 |
| xnview | xnview | 1.25 |
| xnview | xnview | 1.30 |
| xnview | xnview | 1.31 |
| xnview | xnview | 1.32 |
| xnview | xnview | 1.33 |
| xnview | xnview | 1.34 |
| xnview | xnview | 1.35 |
| xnview | xnview | 1.36 |
| xnview | xnview | 1.37 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0153.html
- http://newsgroup.xnview.com/viewtopic.php?f=35&t=28400
- http://osvdb.org/95580
- http://secunia.com/advisories/54174
- http://www.coresecurity.com/advisories/xnview-buffer-overflow-vulnerability
- http://www.exploit-db.com/exploits/27049
- http://www.securitytracker.com/id/1028817
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85919
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0153.html
- http://newsgroup.xnview.com/viewtopic.php?f=35&t=28400
- http://osvdb.org/95580
- http://secunia.com/advisories/54174
- http://www.coresecurity.com/advisories/xnview-buffer-overflow-vulnerability
- http://www.exploit-db.com/exploits/27049
- http://www.securitytracker.com/id/1028817
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85919
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-2577