CVE-2012-0278
Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.
Date published : 2012-04-18
http://www.securityfocus.com/bid/53009
http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=41&Itemid=41