Author: Cyberthreat Blog

CVE-2017-8387

STDU Viewer version 1.6.375 might allow user-assisted attackers to execute code via a crafted file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined...

Read More

CVE-2017-8368

Sublime Text 3 Build 3126 might allow user-assisted attackers to execute code via a crafted .mkv file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined...

Read More

CVE-2017-8381

XnView Classic for Windows Version 2.40 allows user-assisted remote attackers to execute code via a crafted .mkv file that is mishandled during the opening of a directory in “Browser” mode, because of a “User...

Read More

CVE-2017-8369

IrfanView version 4.44 (32bit) has a “Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3” issue, which might allow attackers to execute arbitrary code via a crafted...

Read More

CVE-2017-8370

IrfanView version 4.44 (32bit) with FPX Plugin 4.45 allows remote attackers to execute arbitrary code or cause a denial of service (Heap Corruption and application crash) in processing a FlashPix (.FPX) file, a different...

Read More