peter bassill · operator
$ cve CVE-2007-1263 JSON

CVE-2007-1263 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS5.53% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2007-03-06
Last modified2026-06-16

Affected (2)

VendorProduct
gnugpgme
gnupggnupg

Public exploits

SourceTitleDate
exploit-dbGnuPG 1.x - Signed Message Arbitrary Content Injection2007-03-05

References

→ the Explorer  ·  watch your stack  ·  NVD