← Back

CVE-2013-6932

nvd nist
Published: Dec 28, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.

Affected (12)

Products: Irfanview: Irfanview
1 product
Irfanview
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Irfanview
Up to 4.36
Version 4.00
Version 4.10
Version 4.20
Version 4.23
Version 4.25
Version 4.27
Version 4.28
Version 4.30
Version 4.32
Version 4.33
Version 4.35

References (6)

Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.