Ghisler's vulnerability footprint concentrates in Total Commander, a widely deployed file-management utility, with the recurring signal centered on file-system and code-execution boundary issues such as code injection, path traversal, buffer-boundary violations, and incorrect default permissions. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghisler over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4463MEDIUM The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer i | Aug 21, 2007 | 5.0 | 23 | NO | YES |
CVE-2020-17381HIGH An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replac | Oct 21, 2020 | 7.3 | 22 | NO | NO |
CVE-2007-4756MEDIUM Directory traversal vulnerability in the FTP client in Total Commander before 7.02 allows remote FTP servers to create or overwrite arbitrary files via "..\" (dot dot backslash) se | Sep 8, 2007 | 6.8 | 19 | NO | NO |
CVE-2015-2869MEDIUM The FileInfo plugin before 2.22 for Ghisler Total Commander allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via (1) a large Size val | Jul 21, 2015 | 5.0 | 16 | NO | NO |
CVE-2007-4464MEDIUM CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to spoof the information in the Image File Header tab via string | Aug 21, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghisler.
Media articles that mention a CVE ID that affects a product developed by Ghisler — matched by CVE ID, not by vendor name.