Show filters
61 Total Results
Displaying 1-10 of 61
Sort by:
Attacker Value
Unknown

CVE-2023-31568

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
Attacker Value
Unknown

CVE-2023-31567

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.
Attacker Value
Unknown

CVE-2023-31566

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().
Attacker Value
Unknown

CVE-2023-31556

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.
Attacker Value
Unknown

CVE-2023-31555

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.
Attacker Value
Unknown

CVE-2023-2241

Disclosure Date: April 22, 2023 (last updated February 05, 2025)
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2020-18972

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Attacker Value
Unknown

CVE-2020-18971

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
Attacker Value
Unknown

CVE-2021-30469

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.
Attacker Value
Unknown

CVE-2021-30470

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.