XnView is prone to a security vulnerability when processing MBM files. This vulnerability could be exploited by a remote attacker to execute arbitrary code on the target machine, by enticing the user of XnView to open a specially crafted file.
Disclosure Timeline:
2010-05-27: XnView is notified of the vulnerability.
2010-06-03: The XnView author responds that version 1.97.5 will be available in 2 weeks.
2010-06-14: Advisory is published.