---
id: CVE-2026-107125
title: A flaw has been found in XnView Classic 2.52.5
summary: >-
  A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown
  function of the component FLI File Parser. This manipulation of the argument
  starting_line causes heap-based buffer overflow. Remote exploitation of the
  attack is pos…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-122
vendor: XnView
product: Classic
affected:
  - Classic 2.52.5
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T15:17:18.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107125'
references:
  - url: 'https://newsgroup.xnview.com/viewtopic.php?t=51359'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-107125'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/993948'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/414926'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/414926/cti'
    label: cna@vuldb.com
  - url: 'https://www.xnview.com/en/xnview/#downloads'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T14:33:21.961Z'
---

## Overview

A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
