2026-09-28 21:45CVE-2026-101204VulDB
PUBLISHED5.2ApplicationCWE-125CWE-119x_freeware

FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds

A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Problem type

Affected products

FastStone

Image Viewer

8.0 - AFFECTED

8.1 - AFFECTED

8.2 - AFFECTED

8.3 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-101204
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-101204",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-09-28T21:45:07.824Z",
    "dateReserved": "2026-09-28T09:39:57.518Z",
    "datePublished": "2026-09-28T21:45:07.824Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-09-28T21:45:07.824Z"
      },
      "title": "FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds",
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "affected": [
        {
          "vendor": "FastStone",
          "product": "Image Viewer",
          "cpes": [
            "cpe:2.3:a:faststone:image_viewer:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "TGA Image Handler"
          ],
          "versions": [
            {
              "version": "8.0",
              "status": "affected"
            },
            {
              "version": "8.1",
              "status": "affected"
            },
            {
              "version": "8.2",
              "status": "affected"
            },
            {
              "version": "8.3",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Out-of-Bounds Read",
              "cweId": "CWE-125",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Memory Corruption",
              "cweId": "CWE-119",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/411013",
          "name": "VDB-411013 | FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds",
          "tags": [
            "vdb-entry"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/411013/cti",
          "name": "VDB-411013 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-101204",
          "name": "CVE-2026-101204 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/907608",
          "name": "Submit #907608 | FastStone Soft FastStone Image Viewer 8.3 Out-of-bounds read / information disclosure",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
            "baseScore": 7.5
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-09-28T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-09-28T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-09-28T11:45:31.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "jonzab (VulDB User)",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "VulDB CNA Team",
          "type": "coordinator"
        }
      ],
      "tags": [
        "x_freeware"
      ]
    }
  }
}