CVE-2009-4001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
15/03/2010
Last modified:
11/04/2025

Description

Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xnview:xnview:*:*:*:*:*:*:*:* 1.97.1 (including)
cpe:2.3:a:xnview:xnview:1.0:a:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.01:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.02:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.03:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.04:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.05:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.05:b:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.05:c:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.06:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.07:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.08:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.09:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.10:*:*:*:*:*:*:*
cpe:2.3:a:xnview:xnview:1.11:*:*:*:*:*:*:*