Back cve.threatint.com FastStone Image Viewer 1bpp RLE Decoder out-of-bounds writeA vulnerability ha... CVE: New / 14h A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. The manipulation leads to out-of-bounds write. The...
A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. The manipulation leads to out-of-bounds write. The attack can be initiated remotely. The vendor was contacted early this disclosure but did not respond in any way.
PUBLISHED Reserved 2026-09-28 | Published 2026-09-28 | Updated 2026-09-28 | Assigner VulDB
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P MEDIUM: 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R MEDIUM: 6.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR Problem types Out-of-bounds Write Memory Corruption Product status 8.0 affected 8.1 affected 8.2 affected 8.3 affected Timeline 2026-09-28: Advisory disclosed 2026-09-28: VulDB entry created 2026-09-28: VulDB entry last update Credits jonzab (VulDB User) reporter VulDB CNA Team coordinator References vuldb.com/vuln/411012 (VDB-411012 | FastStone Image Viewer 1bpp RLE Decoder out-of-bounds write) vdb-entry vuldb.com/vuln/411012/cti (VDB-411012 | CTI Indicators (IOB, IOC)) signature permissions-required vuldb.com/cve/CVE-2026-101203 (CVE-2026-101203 | CVE Analysis and Report) third-party-advisory vuldb.com/submit/907575 (Submit #907575 | FastStone Soft FastStone Image Viewer 8.3 Heap-based buffer overflow (out-of-bounds write)) third-party-advisory cve.org (CVE-2026-101203) nvd.nist.gov (CVE-2026-101203) Download JSON
jonzab (VulDB User) reporter
VulDB CNA Team coordinator
vuldb.com/vuln/411012 (VDB-411012 | FastStone Image Viewer 1bpp RLE Decoder out-of-bounds write) vdb-entry
vuldb.com/vuln/411012/cti (VDB-411012 | CTI Indicators (IOB, IOC)) signature permissions-required
vuldb.com/cve/CVE-2026-101203 (CVE-2026-101203 | CVE Analysis and Report) third-party-advisory
vuldb.com/submit/907575 (Submit #907575 | FastStone Soft FastStone Image Viewer 8.3 Heap-based buffer overflow (out-of-bounds write)) third-party-advisory
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
