cve.threatint.com Critical Out-of-Bounds Write Vulnerability in FastStone Image Viewer
Article Content
- •CVE-2026-101203 affects FastStone Image Viewer versions up to 8.3.
- •The vulnerability allows remote attackers to exploit an out-of-bounds write condition.
- •User interaction is required to trigger the vulnerability by opening crafted image files.
A vulnerability, CVE-2026-101203, has been identified in FastStone Image Viewer versions up to 8.3, specifically in the 1bpp RLE Decoder component. This out-of-bounds write vulnerability allows remote attackers to manipulate the application by sending specially crafted image files that require user interaction to open. The attack can lead to memory corruption, potentially compromising the application's integrity and availability. The vendor has been contacted but has not responded to the disclosure. The vulnerability was published on September 28, 2026, and is rated with a CVSS score of 6.3, indicating a high risk if left unpatched. Organizations are advised to avoid opening untrusted image files and to update the application once a patch is available. Currently, there is no evidence of public proof-of-concept exploitation. The attack complexity is low, and no privileges are required for exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-101203 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…