VendorsPDF-XChangepdf-xchange_editorall versions
Vulnerabilities

PDF-XChange Editor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

288CVEs
CVE-2023-42071
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-42078
PDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-42061
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-42051
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-42108
PDF-XChange Editor EMF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2022-42421
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18703.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2023-39488
PDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39491
PDF-XChange Editor TIF File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39496
PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39489
PDF-XChange Editor TIF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2024-27327
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
7.8EPSS 0.004
CVE-2023-39486
PDF-XChange Editor JP2 File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2022-42418
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18677.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2023-39493
PDF-XChange Editor exportAsText Exposed Dangerous Method Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-42111
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-40471
PDF-XChange Editor App Untrusted Pointer Dereference Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39498
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-40472
PDF-XChange Editor JavaScript String Untrusted Pointer Dereference Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39494
PDF-XChange Editor OXPS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2022-41144
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18282.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41150
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18340.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41151
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18341.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41143
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18225.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41147
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18286.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42371
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18346.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42372
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18347.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42373
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18402.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42374
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18403.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42395
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPS files. Crafted data in an XPS file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18274.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2023-39500
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2022-42399
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18327.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42400
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18328.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41148
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18338.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41149
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18339.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-41152
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18342.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2024-8837
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2024-8838
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2024-8831
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2023-39502
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2024-8830
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
← Prev3 / 8Next →