Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.18% | — | PodofoAI | 17/9/2026 | 24/9/2026 | PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine in src/podofo/main/PdfColorSpaceFilter.cpp. PODOFO_INVARIANT does not perform a runtime check, so a… | |
| Aplazada | Baja (2.5) | 0.13% | — | PodofoAI | 14/5/2026 | 17/6/2026 | PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been freed, the Error label frees buf a second time, causing heap corruption. This… | |
| Modificada | Alta (8.1) | 0.40% | — | Podofo Project Podofo | 1/10/2025 | 17/6/2026 | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue. | |
| Analizada | Baja (1.9) | 0.21% | — | Podofo Project Podofo | 24/8/2025 | 17/6/2026 | A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been… | |
| Modificada | Alta (8.8) | 0.76% | — | Podofo Project Podofo | 10/5/2023 | 17/6/2026 | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. | |
| Modificada | Alta (8.8) | 0.75% | — | Podofo Project Podofo | 10/5/2023 | 17/6/2026 | Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. | |
| Modificada | Alta (8.8) | 0.74% | — | Podofo Project Podofo | 10/5/2023 | 17/6/2026 | Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted(). | |
| Modificada | Media (6.5) | 0.70% | — | Podofo Project Podofo | 10/5/2023 | 17/6/2026 | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent. | |
| Modificada | Media (6.5) | 0.64% | — | Podofo Project Podofo | 10/5/2023 | 17/6/2026 | podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad. | |
| Modificada | Alta (7.8) | 0.37% | — | Podofo Project Podofo | 22/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.5) | 0.76% | — | Podofo Project Podofo | 25/8/2021 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'. | |
| Modificada | Media (5.5) | 0.68% | — | Podofo Project Podofo | 25/8/2021 | 17/6/2026 | Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'. | |
| Modificada | Alta (7.8) | 0.76% | — | Podofo Project Podofo | 26/5/2021 | 17/6/2026 | A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value. | |
| Modificada | Media (5.5) | 0.73% | — | Podofo Project PodofoRedhat Enterprise LinuxFedoraproject Fedora | 26/5/2021 | 17/6/2026 | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow. | |
| Modificada | Media (5.5) | 0.69% | — | Podofo Project PodofoRedhat Enterprise LinuxFedoraproject Fedora | 26/5/2021 | 17/6/2026 | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow. | |
| Modificada | Media (5.5) | 0.70% | — | Podofo Project PodofoFedoraproject FedoraRedhat Enterprise Linux | 26/5/2021 | 17/6/2026 | A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file. | |
| Modificada | Media (5.5) | 1.4% | — | Podofo Project PodofoFedoraproject Fedora | 30/12/2019 | 17/6/2026 | The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp. | |
| Modificada | Media (5.5) | 0.98% | — | Podofo Project Podofo | 3/4/2019 | 17/6/2026 | An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated. | |
| Modificada | Crítica (9.8) | 2.2% | — | Podofo Project PodofoFedoraproject Fedora | 11/3/2019 | 17/6/2026 | PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. | |
| Modificada | Media (6.5) | 1.4% | — | Podofo Project Podofo | 27/2/2019 | 17/6/2026 | An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in base/PdfFiltersPrivate.cpp. | |
| Modificada | Alta (8.8) | 2.6% | — | Podofo Project PodofoFedoraproject Fedora | 26/2/2019 | 17/6/2026 | PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. | |
| Modificada | Alta (8.8) | 1.6% | — | Podofo Project Podofo | 4/2/2019 | 17/6/2026 | An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this point is 0x0, which causes a NULL pointer… | |
| Modificada | Alta (8.8) | 1.7% | — | Podofo Project Podofo | 26/11/2018 | 17/6/2026 | A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.5) | 2.4% | — | Podofo Project Podofo | 17/9/2018 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within PdfEncoding::ParseToUnicode. The issue… | |
| Modificada | Alta (7.8) | 0.99% | — | Podofo Project Podofo | 29/6/2018 | 17/6/2026 | A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file. |