Known Vulnerabilities for Qpdf by Qpdf Project
Listed below are 10 of the newest known vulnerabilities associated with "Qpdf" by "Qpdf Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-36978 | QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_A... | 5.5 - MEDIUM | 2021-07-20 | 2024-01-15 |
| CVE-2021-25786 | An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl... | 5.3 - MEDIUM | 2023-08-11 | 2023-09-27 |
| CVE-2018-18020 | In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a lo... | 3.3 - LOW | 2018-10-06 | 2023-08-30 |
| CVE-2018-9918 | libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote... | 7.8 - HIGH | 2018-04-10 | 2019-10-03 |
| CVE-2017-11626 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via... | 5.5 - MEDIUM | 2017-07-25 | 2019-10-03 |
| CVE-2017-11625 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via... | 5.5 - MEDIUM | 2017-07-25 | 2019-10-03 |
| CVE-2017-11624 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via... | 5.5 - MEDIUM | 2017-07-25 | 2019-10-03 |
| CVE-2017-9210 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a... | 5.5 - MEDIUM | 2017-05-23 | 2019-10-03 |
| CVE-2017-9209 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a... | 5.5 - MEDIUM | 2017-05-23 | 2019-10-03 |
| CVE-2017-9208 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a... | 5.5 - MEDIUM | 2017-05-23 | 2019-10-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Qpdf Project | Qpdf | 8.2.1 | All | All | All |
| Application | Qpdf Project | Qpdf | 8.0.2 | All | All | All |
| Application | Qpdf Project | Qpdf | 8.0.1 | All | All | All |
| Application | Qpdf Project | Qpdf | 8.0.0 | rc3 | All | All |
| Application | Qpdf Project | Qpdf | 8.0.0 | rc2 | All | All |
| Application | Qpdf Project | Qpdf | 8.0.0 | rc1 | All | All |
| Application | Qpdf Project | Qpdf | 8.0.0 | a1 | All | All |
| Application | Qpdf Project | Qpdf | 8.0.0 | All | All | All |
| Application | Qpdf Project | Qpdf | 7.1.1 | All | All | All |
| Application | Qpdf Project | Qpdf | 7.1.0 | All | All | All |
| Application | Qpdf Project | Qpdf | 7.0.0 | All | All | All |
| Application | Qpdf Project | Qpdf | 7.0.0 | beta1 | All | All |
| Application | Qpdf Project | Qpdf | 6.0.0 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.2.0 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.1.3 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.1.2 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.1.1 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.1.0 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.0.1 | All | All | All |
| Application | Qpdf Project | Qpdf | 5.0.0 | All | All | All |