Unrated severityNVD Advisory· Published Dec 31, 2006· Updated Apr 23, 2026
CVE-2006-6837
CVE-2006-6837
Description
Multiple stack-based buffer overflows in the (1) LoadTree, (2) ReadHeader, and (3) LoadXBOXTree functions in the ISO (iso_wincmd) plugin 1.7.3.3 and earlier for Total Commander allow user-assisted remote attackers to execute arbitrary code via a long pathname in an ISO image.
Affected products
2cpe:2.3:a:sergey_oblomov:iso_wincmd:1.6.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sergey_oblomov:iso_wincmd:1.6.10:*:*:*:*:*:*:*
- cpe:2.3:a:sergey_oblomov:iso_wincmd:1.7.3.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- vuln.sg/isowincmd173-en.htmlnvdExploitVendor Advisory
- vuln.sg/isowincmd173-jp.htmlnvdExploitVendor Advisory
- secunia.com/advisories/23599nvdVendor Advisory
- securityreason.com/securityalert/2088nvd
- securitytracker.com/idnvd
- www.securityfocus.com/archive/1/455547/100/0/threadednvd
- www.securityfocus.com/bid/21820nvd
- www.vupen.com/english/advisories/2007/0008nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/31180nvd
News mentions
0No linked articles in our index yet.