CVE-2013-5351 describes a heap-based buffer overflow vulnerability in IrfanView versions prior to 4.37, allowing remote attackers to execute arbitrary code by crafting a malicious GIF file with a specially designed LZW code stream. This vulnerability carries a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it is not listed in CISA's KEV catalog, its FAUCET Risk Score of 65/100 suggests a notable risk. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.36CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:*:*:*:*:*:*:*:* | ||
1.70CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.70:*:*:*:*:*:*:* | ||
1.75CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.75:*:*:*:*:*:*:* | ||
1.80CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.80:*:*:*:*:*:*:* | ||
1.85CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.85:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.