2026-09-28 21:15CVE-2026-101202VulDB
PUBLISHED5.2ApplicationCWE-787CWE-119x_freeware

FastStone Image Viewer TGA Image out-of-bounds write

A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-bounds write. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Problem type

Affected products

FastStone

Image Viewer

8.0 - AFFECTED

8.1 - AFFECTED

8.2 - AFFECTED

8.3 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-101202
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-101202",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-09-28T21:15:09.255Z",
    "dateReserved": "2026-09-28T09:39:49.253Z",
    "datePublished": "2026-09-28T21:15:09.255Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-09-28T21:15:09.255Z"
      },
      "title": "FastStone Image Viewer TGA Image out-of-bounds write",
      "descriptions": [
        {
          "lang": "en",
          "value": "A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-bounds write. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "affected": [
        {
          "vendor": "FastStone",
          "product": "Image Viewer",
          "cpes": [
            "cpe:2.3:a:faststone:image_viewer:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "TGA Image Handler"
          ],
          "versions": [
            {
              "version": "8.0",
              "status": "affected"
            },
            {
              "version": "8.1",
              "status": "affected"
            },
            {
              "version": "8.2",
              "status": "affected"
            },
            {
              "version": "8.3",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Out-of-bounds Write",
              "cweId": "CWE-787",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Memory Corruption",
              "cweId": "CWE-119",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/411011",
          "name": "VDB-411011 | FastStone Image Viewer TGA Image out-of-bounds write",
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/411011/cti",
          "name": "VDB-411011 | CTI Indicators (IOB, IOC)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-101202",
          "name": "CVE-2026-101202 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/907574",
          "name": "Submit #907574 | FastStone Soft FastStone Image Viewer 8.3 Heap-based buffer overflow (out-of-bounds write)",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
            "baseScore": 7.5
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-09-28T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-09-28T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-09-28T11:45:21.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "jonzab (VulDB User)",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "VulDB CNA Team",
          "type": "coordinator"
        }
      ],
      "tags": [
        "x_freeware"
      ]
    }
  }
}