Improper input validation - CVE-2017-10748
Published: October 6, 2017 / Updated: October 16, 2017
Vulnerability identifier: #VU8717
CSH Severity: Medium
CVSS v4.0:
CVE-ID: CVE-2017-10748
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor:
Affected software:
Detailed vulnerability description
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."