CVE-2013-5351: Irfanview

High severity, CVSS 7.5. EPSS: 5% chance of exploitation in the next 30 days.

Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.

Affected products

  • Irfanview Irfanview: up to and including 4.36; version 1.70 only; version 1.75 only; version 1.80 only; version 1.85 only; version 1.90 only; …

Published 2014-02-14. Last modified 2026-06-16.