CVE-2013-6932

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
irfanviewirfanview
𝑥
≤ 4.36
irfanviewirfanview
4.00
irfanviewirfanview
4.10
irfanviewirfanview
4.20
irfanviewirfanview
4.23
irfanviewirfanview
4.25
irfanviewirfanview
4.27
irfanviewirfanview
4.28
irfanviewirfanview
4.30
irfanviewirfanview
4.32
irfanviewirfanview
4.33
irfanviewirfanview
4.35
𝑥
= Vulnerable software versions