CVE-2026-101204
Received Received - Intake

Out-of-Bounds Read in FastStone Image Viewer TGA Handler

Vulnerability report for CVE-2026-101204, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
faststone faststone_image_viewer to 8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read issue in FastStone Image Viewer up to version 8.3. It affects the TGA Image Handler component in the FSViewer.exe file. An attacker can exploit this remotely by manipulating the application to read memory outside its intended bounds.

Detection Guidance

This vulnerability affects FastStone Image Viewer up to version 8.3, specifically the TGA Image Handler component. Detection involves checking installed versions of FastStone Image Viewer. Use commands like 'wmic product get name,version' on Windows or 'dpkg -l | grep faststone' on Linux to verify the version.

Impact Analysis

This vulnerability may allow attackers to read sensitive memory data, potentially leading to information disclosure. It could cause crashes or unexpected behavior in the application. However, the impact is limited due to the low CVSS scores.

Compliance Impact

The vulnerability is an out-of-bounds read in FastStone Image Viewer, which could potentially allow unauthorized access to memory. This may lead to information disclosure but does not directly indicate data breaches or compliance violations. Its impact on GDPR or HIPAA depends on whether sensitive data is exposed, but the CVE itself does not provide evidence of such exposure.

Mitigation Strategies

Immediate mitigation steps include updating FastStone Image Viewer to the latest version if available, or uninstalling the software if no update is provided. Disable or restrict access to the TGA Image Handler component if possible. Monitor vendor communications for patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101204. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart