
Cloud Vulnerability DB
A community-led vulnerabilities database
XnView MP version 0.96.4 was discovered to contain a heap overflow vulnerability which allows attackers to cause a denial of service (DoS) via a crafted ico file (NVD).
The vulnerability exists in the SmartStretchDIBits function within USER32.dll when processing ICO files. When XnView opens a carefully constructed ico file, it triggers an access violation at USER32!SmartStretchDIBits+0x33, leading to a read access violation and potential heap overflow (Github Vuln).
The vulnerability can lead to denial of service conditions when processing specially crafted ICO files, causing the application to crash. This affects the stability and availability of the XnView MP application (NVD).
Users should upgrade to a version newer than 0.96.4. XnView MP has released multiple versions since then, with the latest being 1.8.6, which likely contains fixes for this vulnerability (XnView).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."