VYPR
Unrated severityNVD Advisory· Published May 16, 2006· Updated Apr 16, 2026

CVE-2006-2407

CVE-2006-2407

Description

Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.

Affected products

4
  • cpe:2.3:a:freeftpd:freeftpd:1.0.10:*:*:*:*:*:*:*
  • cpe:2.3:a:freesshd:freesshd:1.0.9:*:*:*:*:*:*:*
  • cpe:2.3:a:weonlydo:wodsshserver:1.2.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:weonlydo:wodsshserver:1.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:weonlydo:wodsshserver:1.3.3_demo:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

18

News mentions

0

No linked articles in our index yet.