← Vulnerability feed

Vulnerability record · CVE-2012-0897 · published 20 January 2012

CVE-2012-0897: IrfanView JPEG2000 plugin stack buffer overflow via crafted QCD marker

Irfanview · Irfanview

The JPEG2000 plugin in IrfanView PlugIns before 4.33 has a stack-based buffer overflow triggered by a JP2 file containing a crafted Quantization Default (QCD) marker segment. Opening such a file can corrupt the stack and allow code execution in the context of the user running IrfanView.

6.8 CVSS 2.0 Medium EPSS 52% · top 1.1% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution via a common file format with a high EPSS score, though exploitation requires user interaction and no KEV listing exists.

What it is

The JPEG2000 plugin in IrfanView PlugIns before 4.33 has a stack-based buffer overflow triggered by a JP2 file containing a crafted Quantization Default (QCD) marker segment. Opening such a file can corrupt the stack and allow code execution in the context of the user running IrfanView.

Impact

An attacker who gets a victim to open a malicious JP2 file can execute arbitrary code with the privileges of the IrfanView process, potentially leading to full system compromise.

Attack surface

Reached remotely by delivering a crafted JP2 file that the user opens in IrfanView; no authentication is required, but user interaction (opening the file) is needed per the AV:N/AC:M/Au:N vector.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is high (0.522, 98.9th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Update IrfanView PlugIns to version 4.33 or later, which fixes the flaw.
  • If immediate patching is not possible, restrict or disable the JPEG2000 plugin and avoid opening untrusted JP2 files.
  • Block JP2 attachments at email and web gateways where feasible.
  • Train users not to open image files from untrusted sources.
  • Monitor vendor advisories for any further updates to the plugin.

Detection

  • Hunt for IrfanView processes spawning child processes or making unexpected network connections after opening image files.
  • Monitor for crashes or access violations in the IrfanView JPEG2000 plugin module.
  • Scan email and file transfer logs for JP2 files delivered from external or untrusted senders.
  • Use endpoint detection to flag stack corruption or exploit-like behavior in image viewer processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0897 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-1867Irfanview vulnerabilityBuffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.EPSS 7.9%9.3CVE-2008-0493Irfanview memory buffer overflow vulnerabilityfpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which…EPSS 8.7%9.3CVE-2007-1948Irfanview vulnerabilityBuffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xof…EPSS 8.3%8.8CVE-2020-13905Irfanview vulnerabilityIrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000038ed4.EPSS 3.2%8.5CVE-2007-2363Irfanview vulnerabilityBuffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.EPSS 8.9%7.8CVE-2024-9258Irfanview vulnerabilityIrfanView SID File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…EPSS 0.36%7.8CVE-2024-9259Irfanview out-of-bounds write vulnerabilityIrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…EPSS 0.35%7.8CVE-2024-9260Irfanview out-of-bounds write vulnerabilityIrfanView SID File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2012-0897), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.