Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Podofo HIGH 8.1
CVE-2025-46205

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) b…

Fix: after 0.10.5
Fix from $1,950 2025-10-01
Podofo MEDIUM 5.5
CVE-2025-9394

A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.c…

Patch available
Fix from $1,600 2025-08-24
Podofo HIGH 8.8
CVE-2023-31566

Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().

Patch available
Fix from $1,950 2023-05-10
Podofo HIGH 8.8
CVE-2023-31567

Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.

Patch available
Fix from $1,950 2023-05-10
Podofo HIGH 8.8
CVE-2023-31568

Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.

Patch available
Fix from $1,950 2023-05-10
Podofo MEDIUM 6.5
CVE-2023-31555

podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.

Patch available
Fix from $1,600 2023-05-10
Podofo MEDIUM 6.5
CVE-2023-31556

podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.

Patch available
Fix from $1,600 2023-05-10
Podofo MEDIUM 5.3
CVE-2023-2241

A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStream…

Patch available
Fix from $1,600 2023-04-22
Podofo MEDIUM 5.5
CVE-2020-18972

Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the…

No fix yet
Fix from $1,600 2021-08-25
Podofo MEDIUM 5.5
CVE-2020-18971

Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.

No fix yet
Fix from $1,600 2021-08-25
Podofo HIGH 7.8
CVE-2021-30472

A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because …

Patch available
Fix from $1,950 2021-05-26
Podofo MEDIUM 5.5
CVE-2019-10723

An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation becaus…

No fix yet
Fix from $1,600 2019-04-03
Podofo MEDIUM 6.5
CVE-2018-20797

An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp w…

No fix yet
Fix from $1,600 2019-02-27
Podofo HIGH 8.8
CVE-2018-20751

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var)…

No fix yet
Fix from $1,950 2019-02-04
Podofo HIGH 8.8
CVE-2018-19532

A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the P…

Patch available
Fix from $1,950 2018-11-26
Podofo MEDIUM 6.5
CVE-2018-14320

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to e…

Mitigation only
Fix from $1,600 2018-09-17
Podofo HIGH 7.8
CVE-2018-12983

A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by …

No fix yet
Fix from $1,950 2018-06-29
Podofo MEDIUM 5.5
CVE-2018-12982

Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-s…

No fix yet
Fix from $1,600 2018-06-29
Podofo MEDIUM 6.5
CVE-2018-11256

An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a den…

No fix yet
Fix from $1,600 2018-05-18
Podofo MEDIUM 5.5
CVE-2018-11254

An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote atta…

Mitigation only
Fix from $1,600 2018-05-18
Podofo MEDIUM 5.5
CVE-2018-11255

An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a deni…

No fix yet
Fix from $1,600 2018-05-18
Podofo HIGH 8.8
CVE-2018-8000

In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue…

No fix yet
Fix from $1,950 2018-03-09
Podofo HIGH 8.8
CVE-2018-8002EPSS 8%

In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack…

No fix yet
Fix from $1,950 2018-03-09
Podofo HIGH 7.8
CVE-2018-8001

In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vuln…

Mitigation only
Fix from $1,950 2018-03-09
Podofo MEDIUM 5.5
CVE-2018-6352

In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverag…

Mitigation only
Fix from $1,600 2018-01-27
Podofo MEDIUM 5.5
CVE-2018-5783

In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers c…

No fix yet
Fix from $1,600 2018-01-19
Podofo HIGH 7.8
CVE-2018-5308

PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers co…

No fix yet
Fix from $1,950 2018-01-09
Podofo MEDIUM 5.5
CVE-2018-5309

In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cp…

No fix yet
Fix from $1,600 2018-01-09
Podofo MEDIUM 5.5
CVE-2018-5295

In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote att…

No fix yet
Fix from $1,600 2018-01-08
Podofo MEDIUM 5.5
CVE-2018-5296

In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers coul…

No fix yet
Fix from $1,600 2018-01-08