cbcvebase.
CVE-2013-1927
published 2013-04-29

CVE-2013-1927: The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF…

PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.32%
90.1th percentile
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianicedtea-web< icedtea-web 1.3.2-1 (bookworm)icedtea-web 1.3.2-1 (bookworm)
opensuseopensuse
python-gnupg_projectpython-gnupg>= 0.3.5 < 0.3.60.3.6
redhaticedtea-web<= 1.2.2
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web
redhaticedtea-web

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.