CVE-2013-6932: Irfanview

High severity, CVSS 7.6. EPSS: 5.7% chance of exploitation in the next 30 days.

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.

Affected products

  • Irfanview Irfanview: up to and including 4.36; version 4.00 only; version 4.10 only; version 4.20 only; version 4.23 only; version 4.25 only; …

Published 2013-12-28. Last modified 2026-06-17.