Podofo Project
Podofo Project Podofo: vulnerabilities and CVEs
Podofo Project Podofo has 63 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs63
Last 12 months0
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46205 | High (8.1) | 0.40% | — | Oct 1, 2025 | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier… |
| CVE-2025-9394 | Low (1.9) | 0.21% | — | Aug 24, 2025 | A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executing manipulation can… |
| CVE-2023-31568 | High (8.8) | 0.76% | — | May 10, 2023 | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. |
| CVE-2023-31567 | High (8.8) | 0.75% | — | May 10, 2023 | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. |
| CVE-2023-31566 | High (8.8) | 0.74% | — | May 10, 2023 | Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted(). |
| CVE-2023-31556 | Medium (6.5) | 0.70% | — | May 10, 2023 | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent. |
| CVE-2023-31555 | Medium (6.5) | 0.64% | — | May 10, 2023 | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad. |
| CVE-2023-2241 | High (7.8) | 0.37% | — | Apr 22, 2023 | A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer… |
| CVE-2020-18972 | Medium (5.5) | 0.76% | — | Aug 25, 2021 | Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'. |
| CVE-2020-18971 | Medium (5.5) | 0.68% | — | Aug 25, 2021 | Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'. |
| CVE-2021-30472 | High (7.8) | 0.76% | — | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value. |
| CVE-2021-30471 | Medium (5.5) | 0.73% | — | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow. |
| CVE-2021-30470 | Medium (5.5) | 0.69% | — | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow. |
| CVE-2021-30469 | Medium (5.5) | 0.70% | — | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file. |
| CVE-2019-20093 | Medium (5.5) | 1.4% | — | Dec 30, 2019 | The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp. |
| CVE-2019-10723 | Medium (5.5) | 0.98% | — | Apr 3, 2019 | An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated. |
| CVE-2019-9687 | Critical (9.8) | 2.2% | — | Mar 11, 2019 | PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. |
| CVE-2018-20797 | Medium (6.5) | 1.4% | — | Feb 27, 2019 | An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in… |
| CVE-2019-9199 | High (8.8) | 2.6% | — | Feb 26, 2019 | PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an… |
| CVE-2018-20751 | High (8.8) | 1.6% | — | Feb 4, 2019 | An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for… |
| CVE-2018-19532 | High (8.8) | 1.7% | — | Nov 26, 2018 | A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to… |
| CVE-2018-14320 | Medium (6.5) | 2.4% | — | Sep 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must visit a malicious… |
| CVE-2018-12983 | High (7.8) | 0.99% | — | Jun 29, 2018 | A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file. |
| CVE-2018-12982 | Medium (5.5) | 1.1% | — | Jun 29, 2018 | Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file. |
| CVE-2018-11256 | Medium (6.5) | 1.4% | — | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a… |
| CVE-2018-11255 | Medium (5.5) | 1.1% | — | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a… |
| CVE-2018-11254 | Medium (5.5) | 1.1% | — | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a denial of service… |
| CVE-2018-8002 | High (8.8) | 8.0% | — | Mar 9, 2018 | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause… |
| CVE-2018-8001 | High (7.8) | 1.3% | — | Mar 9, 2018 | In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other… |
| CVE-2018-8000 | High (8.8) | 2.8% | — | Mar 9, 2018 | In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attackers could leverage this vulnerability… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.