VendorsPDF-XChangepdf-xchange_editorall versions
Vulnerabilities

PDF-XChange Editor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

288CVEs
CVE-2024-8821
PDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
5.5EPSS 0.004
CVE-2022-42414
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18326.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2023-40468
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-40473
PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2024-27324
PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-01 · Analyzed
5.5EPSS 0.004
CVE-2024-27328
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-01 · Analyzed
5.5EPSS 0.004
CVE-2023-39487
PDF-XChange Editor util Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2024-27325
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-01 · Analyzed
5.5EPSS 0.004
CVE-2022-42408
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18543.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2024-27326
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-01 · Analyzed
5.5EPSS 0.004
CVE-2024-27329
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-01 · Analyzed
5.5EPSS 0.004
CVE-2023-42106
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42107
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42109
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42110
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42112
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-42113
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-39504
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-39505
PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-40470
PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-39495
PDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2024-8844
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
5.5EPSS 0.004
CVE-2024-8845
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
5.5EPSS 0.004
CVE-2024-8832
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
5.5EPSS 0.004
CVE-2024-8836
PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
5.5EPSS 0.004
CVE-2023-40469
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2023-39503
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
5.5EPSS 0.004
CVE-2022-42406
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18369.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42407
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18542.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42384
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18653.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2024-8843
PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
5.5EPSS 0.004
CVE-2022-41145
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18283.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-41146
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18284.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42388
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18657.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42389
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18658.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42390
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18659.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42391
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18660.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42392
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18661.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42393
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18662.
Published 2023-01-26 · Modified
5.5EPSS 0.004
CVE-2022-42375
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18404.
Published 2023-01-26 · Modified
5.5EPSS 0.004
← Prev6 / 8Next →