Search CVE reports


Toggle filters

1 – 10 of 63 results


CVE-2025-9394

Medium priority
Needs evaluation

A flaw has been found in PoDoFo 1.1.0-dev. This issue affects the function PdfTokenizer::DetermineDataType of the file src/podofo/main/PdfTokenizer.cpp of the component PDF Dictionary Parser. Executing manipulation can lead to use...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-31568

Medium priority
Ignored

Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31567

Medium priority
Ignored

Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31566

Medium priority
Ignored

Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31556

Medium priority
Ignored

podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-31555

Medium priority
Ignored

podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfObject::DelayedLoad.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-2241

Medium priority
Ignored

A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-30472

Medium priority
Needs evaluation

A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-30471

Medium priority

Some fixes available 2 of 8

A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Fixed Fixed Not affected
Show less packages

CVE-2021-30470

Medium priority

Some fixes available 2 of 8

A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Fixed Fixed Not affected
Show less packages