VendorsPDF-XChangepdf-xchange_editorall versions
Vulnerabilities

PDF-XChange Editor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

288CVEs
CVE-2023-24308
A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file.
Published 2023-03-28 · Modified
7.8EPSS 0.002
CVE-2018-16303
PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a related issue to CVE-2003-1564.
Published 2018-09-01 · Modified
7.5EPSS 0.016
CVE-2024-27323
PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
7.5EPSS 0.003
CVE-2025-64085
A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-12-09 · Modified
7.5EPSS 0.003
CVE-2025-64086
A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-12-09 · Modified
7.5EPSS 0.003
CVE-2019-17497
Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction.
Published 2019-10-10 · Modified
6.5EPSS 0.063
CVE-2025-27931
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Published 2025-08-05 · Modified
6.5EPSS 0.005
CVE-2025-58113
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Published 2025-12-02 · Analyzed
6.5EPSS 0.005
CVE-2025-47152
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Published 2025-08-05 · Modified
6.5EPSS 0.005
CVE-2022-37351
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17636.
Published 2023-03-29 · Modified
5.5EPSS 0.009
CVE-2022-37360
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17635.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37375
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPC files. Crafted data in a JPC file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18069.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37373
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17810.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37361
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. Crafted data in a JP2 file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17674.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37368
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17728.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37352
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WMF files. Crafted data in a WMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17638.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37353
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17637.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2022-37370
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17725.
Published 2023-03-29 · Modified
5.5EPSS 0.007
CVE-2023-27338
PDF-XChange Editor TIF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.006
CVE-2023-42056
PDF-XChange Editor U3D File Parsing Uninitialized Variable Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.005
CVE-2023-39483
PDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.005
CVE-2023-42050
PDF-XChange Editor EMF File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.005
CVE-2023-42046
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.005
CVE-2023-42048
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42079
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42073
PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-39484
PDF-XChange Editor PDF File Parsing Uninitialized Variable Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42054
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42052
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42070
PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42087
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42065
PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42081
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42067
PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42072
PDF-XChange Editor JPC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42066
PDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42053
PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42049
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42068
PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42084
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
← Prev5 / 8Next →