Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.
2013-12-28T04:53:06.727
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.6 (HIGH)
AV:N/AC:H/Au:N/C:C/I:C/A:C
4.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | irfanview | irfanview | ≤ 4.36 | Yes |
Application | irfanview | irfanview | 4.00 | Yes |
Application | irfanview | irfanview | 4.10 | Yes |
Application | irfanview | irfanview | 4.20 | Yes |
Application | irfanview | irfanview | 4.23 | Yes |
Application | irfanview | irfanview | 4.25 | Yes |
Application | irfanview | irfanview | 4.27 | Yes |
Application | irfanview | irfanview | 4.28 | Yes |
Application | irfanview | irfanview | 4.30 | Yes |
Application | irfanview | irfanview | 4.32 | Yes |
Application | irfanview | irfanview | 4.33 | Yes |
Application | irfanview | irfanview | 4.35 | Yes |