VendorsArtifexmupdfany version
Vulnerabilities

Artifex Mupdf any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2016-6525
Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array.
Published 2016-09-22 · Modified
9.8EPSS 0.038
CVE-2018-1000038
In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file.
Published 2018-05-24 · Modified
7.8EPSS 0.020
CVE-2018-1000039
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Published 2018-05-24 · Modified
7.8EPSS 0.018
CVE-2017-17866
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.
Published 2017-12-23 · Modified
7.8EPSS 0.016
CVE-2017-15369
The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a register, which allows remote attackers to cause a denial of service (Fitz fz_drop_imp use-after-free and application crash) or possibly have unspecified other impact via a crafted PDF document.
Published 2017-10-16 · Modified
7.8EPSS 0.013
CVE-2020-16600
A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.
Published 2020-12-09 · Modified
7.8EPSS 0.010
CVE-2017-5991
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.
Published 2017-02-15 · Modified
7.51 PoCEPSS 0.152
CVE-2014-2013
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.
Published 2014-03-03 · Modified
7.51 PoCEPSS 0.145
CVE-2026-25556
MuPDF 1.23.0 through 1.27.0 Barcode Decoding Double Free
Published 2026-02-06 · Analyzed
7.5EPSS 0.007
CVE-2025-55780
A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.
Published 2025-09-23 · Analyzed
7.5EPSS 0.004
CVE-2019-14975
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
Published 2019-08-14 · Modified
7.1EPSS 0.011
CVE-2025-71382
MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
Published 2026-06-23 · Analyzed
7.1EPSS 0.006
CVE-2025-46206
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
Published 2025-08-04 · Modified
6.5EPSS 0.004
CVE-2026-7233
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
Published 2026-04-28 · Modified
6.1EPSS 0.002
CVE-2017-5896
Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c in MuPDF 1.10a allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted image.
Published 2017-02-15 · Modified
5.5EPSS 0.017
CVE-2016-6265
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
Published 2016-09-22 · Modified
5.5EPSS 0.016
CVE-2016-10247
Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
Published 2017-03-16 · Modified
5.5EPSS 0.016
CVE-2018-1000037
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
Published 2018-05-24 · Modified
5.5EPSS 0.016
CVE-2016-10246
Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
Published 2017-03-16 · Modified
5.5EPSS 0.015
CVE-2018-1000040
In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.
Published 2018-05-24 · Modified
5.5EPSS 0.015
CVE-2016-8674
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
Published 2017-02-15 · Modified
5.5EPSS 0.014
CVE-2021-37220
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
Published 2021-07-21 · Modified
5.5EPSS 0.013
CVE-2020-19609
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.
Published 2021-07-21 · Modified
5.5EPSS 0.010
CVE-2020-26519
Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.
Published 2020-10-02 · Modified
5.5EPSS 0.010
CVE-2018-1000036
In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
Published 2018-05-24 · Modified
5.5EPSS 0.010
CVE-2021-4216
A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.
Published 2022-08-26 · Modified
5.5EPSS 0.002
CVE-2026-40505
MuPDF < 1.27 mutool ANSI Injection via Metadata
Published 2026-04-16 · Analyzed
4.8EPSS 0.002