CVE-2026-30041: Integer Overflow
Published Jun 26, 2026
·Updated
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
Affected Software
1 affected component
FastStone FastStone Image Viewer=8.3
Event History
Jun 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Systems running FastStone Image Viewer v8.3 are exposed when the application parses an attacker-supplied PSD file. The network attack vector and lack of required privileges or user interaction in the CVSS data indicate the flaw can be triggered without authentication.
2
What can an attacker achieve?
A crafted PSD file can trigger an integer overflow in the PSD parser, potentially resulting in arbitrary code execution or a denial of service. The reported CVSS v3.1 vector rates availability impact as high, with no reported confidentiality or integrity impact.