Skip to content

CVE-2012-4988

Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.3494 (34.9%)
Percentile: 97.0%
EPSS: 2026-05-06

Affects

xnview:xnview

Technical description

Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99.1 allows remote attackers to execute arbitrary code via a crafted JLS image file.

Published: 7/9/2014, 2:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam