VendorsPDF-XChangepdf-xchange_editorall versions
Vulnerabilities

PDF-XChange Editor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

288CVEs
CVE-2023-39501
PDF-XChange Editor OXPS File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39502
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2023-39497
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2022-42370
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18345.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42394
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18893.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2023-39492
PDF-XChange Editor PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.8EPSS 0.004
CVE-2024-8842
PDF-XChange Editor RTF File Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2022-42402
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in an embedded U3D object can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18632.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42396
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18278.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42405
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18367.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42378
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18631.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42379
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18648.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42380
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18649.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42381
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18650.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42382
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18651.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2022-42410
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PGM files. Crafted data in a PGM file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18365.
Published 2023-01-26 · Modified
7.8EPSS 0.004
CVE-2024-8825
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2024-8826
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2024-8827
PDF-XChange Editor PPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2024-8840
PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.004
CVE-2022-42377
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18630.
Published 2023-01-26 · Modified
7.8EPSS 0.003
CVE-2024-8818
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2024-8814
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2024-8815
PDF-XChange Editor U3D File Parsing Memory Corruption Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2024-8833
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2024-8812
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2024-8813
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2025-2231
PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2025-03-24 · Analyzed
7.8EPSS 0.003
CVE-2025-6660
PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2024-8817
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2024-8847
PDF-XChange Editor Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2024-11-22 · Analyzed
7.8EPSS 0.003
CVE-2025-6640
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6644
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6645
PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6661
PDF-XChange Editor App Object Use-After-Free Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6654
PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6651
PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6659
PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6647
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
CVE-2025-6642
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
7.8EPSS 0.003
← Prev4 / 8Next →