VendorsiTextPDFitextall versions
Vulnerabilities

iTextPDF iText

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-43113
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
Published 2021-12-15 · Modified
9.8EPSS 0.052
CVE-2017-9096
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.
Published 2017-11-08 · Modified
8.8EPSS 0.096
CVE-2022-24196
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Published 2022-02-01 · Modified
6.5EPSS 0.016
CVE-2022-24197
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Published 2022-02-01 · Modified
6.5EPSS 0.015
CVE-2023-6298
Apryse iText PdfDocument.java main array index
Published 2023-11-26 · Modified
6.5EPSS 0.011
CVE-2023-6299
Apryse iText Reference Table PdfDocument.java memory leak
Published 2023-11-26 · Modified
6.5EPSS 0.009
CVE-2022-24198
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be exploitable.
Published 2022-02-01 · Modified
6.5EPSS 0.005