← All CVEs

CVE-2006-2407

high · 7.5

Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.

7.5
CVSS
71.4%
EPSS (exploit prob.)
99th
EPSS percentile
2006-05-16
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
freeftpdfreeftpd1.0.10
freesshdfreesshd1.0.9
weonlydowodsshserver1.2.7
weonlydowodsshserver1.3.3_demo

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-2407