Unrated severityNVD Advisory· Published Aug 21, 2007· Updated Apr 23, 2026
CVE-2007-4463
CVE-2007-4463
Description
The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.
Affected products
2- cpe:2.3:a:fransois_gannier:fileinfo_plugin:2.09:*:*:*:*:*:*:*
- cpe:2.3:a:ghisler:total_commander:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/25373nvdExploit
- blog.hispasec.com/lab/230nvd
- blog.hispasec.com/lab/advisories/adv_Fileinfo-2_09_multiple_vulnerabilities.txtnvd
- osvdb.org/46835nvd
- securityreason.com/securityalert/3044nvd
- www.securityfocus.com/archive/1/477170/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36126nvd
News mentions
0No linked articles in our index yet.