Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-30040 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-122Heap-based Buffer OverflowCISA-ADP

Affected Products

ProductVersions
FastStone Image Viewer
<= 8.3

CPE

  • cpe:2.3:a:faststone:image_viewer:*:*:*:*:*:*:*:*
  • cpe:2.3:a:faststone:faststone_image_viewer:*:*:*:*:*:*:*:*
  • cpe:2.3:a:faststone_soft:faststone_image_viewer:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 8.5moderate efforthttps://www.faststonesoft.net/DN/FSViewerSetup85.exe
  • Workaround:low effort

    Run FastStone Image Viewer using a restricted local account and enforce policies to prevent users from downloading or saving JP2 or PSD files from untrusted sources.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-30040
NVD Published Date:
Jun 26, 2026
NVD Last Modified:
Jun 26, 2026
Source:
[email protected]
CVE-2026-30040 Details - Not Deferred