Known Vulnerabilities for products from Podofo Project
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Podofo Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-9394 json | A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/po... | Not Provided | 2025-08-24 | 2026-04-29 |
| CVE-2023-31568 json | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. | 8.8 - HIGH | 2023-05-10 | 2023-05-15 |
| CVE-2023-31567 json | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. | 8.8 - HIGH | 2023-05-10 | 2023-05-15 |
| CVE-2023-31566 json | Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted(). | 8.8 - HIGH | 2023-05-10 | 2023-05-15 |
| CVE-2023-31556 json | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent. | 6.5 - MEDIUM | 2023-05-10 | 2023-05-17 |
| CVE-2023-31555 json | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad. | 6.5 - MEDIUM | 2023-05-10 | 2023-05-17 |
| CVE-2023-2241 json | A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry o... | 7.8 - HIGH | 2023-04-22 | 2023-11-07 |
| CVE-2021-30472 json | A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.... | 7.8 - HIGH | 2021-05-26 | 2022-12-21 |
| CVE-2021-30471 json | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/... | 5.5 - MEDIUM | 2021-05-26 | 2022-12-21 |
| CVE-2021-30470 json | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVarian... | 5.5 - MEDIUM | 2021-05-26 | 2022-12-21 |
| CVE-2021-30469 json | A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service ... | 5.5 - MEDIUM | 2021-05-26 | 2022-12-21 |
| CVE-2020-18972 json | Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information ... | 5.5 - MEDIUM | 2021-08-25 | 2021-09-07 |
| CVE-2020-18971 json | Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDic... | 5.5 - MEDIUM | 2021-08-25 | 2021-09-07 |
| CVE-2019-20093 json | The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of ser... | 5.5 - MEDIUM | 2019-12-30 | 2023-11-07 |
| CVE-2019-10723 json | An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive ... | 5.5 - MEDIUM | 2019-04-03 | 2020-08-24 |
| CVE-2019-9687 json | PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. | 9.8 - CRITICAL | 2019-03-11 | 2023-11-07 |
| CVE-2019-9199 json | PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for ... | 8.8 - HIGH | 2019-02-26 | 2023-11-07 |
| CVE-2018-20797 json | An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/P... | 6.5 - MEDIUM | 2019-02-27 | 2019-02-27 |
| CVE-2018-20751 json | An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(... | 8.8 - HIGH | 2019-02-04 | 2019-02-08 |
| CVE-2018-19532 json | A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9... | 8.8 - HIGH | 2018-11-26 | 2018-12-19 |
Known software with vulnerabilities from Podofo Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Podofo Project | Podofo | - |