CVE-2026-107125 PUBLISHED

XnView Classic FLI File heap-based overflow

Assigner: VulDB
Reserved: 07.10.2026 Published: 07.10.2026 Updated: 07.10.2026

A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor XnView
Product Classic
Versions
  • Version 2.52.5 is affected
  • Version 2.52.6 is unaffected

Credits

  • jonzab (VulDB User) reporter

References

Problem Types

  • Heap-based Buffer Overflow CWE
  • Memory Corruption CWE