Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/84642
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-3184
http://www.fuzzmyapp.com/advisories/FMA-2013-003/FMA-2013-003-EN.xml