📦

nconvert

Vendor: pierreegougelet

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.97% Exploit Prob.
Latest CVE CVE-2026-30007 Mar 23

Security Vulnerability Index

Page 1 / 1
6.2 CVSS

XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file

EPSS: 0.16%
6.2 CVSS

XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.

EPSS: 0.16%
6.5 CVSS

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

EPSS: 1.13%
7.8 CVSS

XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

EPSS: 0.54%
7.8 CVSS

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

EPSS: 0.52%
7.8 CVSS

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

EPSS: 0.62%
9.3 CVSS
CVE-2008-2427
Exploit Found

Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.

EPSS: 16.06%
9.3 CVSS

Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.

EPSS: 4.61%