CVE-2026-107125EPSS p22.5%
CVE-2026-107125CVE-2026-107125
Description
A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.
Scoring
| CVSS | 6.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
| EPSS | 0.32% probability of exploitation · percentile 22.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |