Glyph & Cog, LLC
First CVE: May 11, 2023Active for: 3 years
19
CVEs Published
More CVEs Published than 38% of tracked CNAs
4.8
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
4.7
Avg CVSS Score
Higher Avg CVSS Score than 2% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Glyph & Cog, LLC over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2023
3 years ago
Most Recent CVE
Mar 18, 2026
128 days ago
Top CVEs
All CVEs published by Glyph & Cog, LLC as a CNA, regardless of affected vendor or product.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7868HIGH In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault att | Aug 15, 2024 | 8.2 | 22 | NO | NO |
CVE-2024-3248MEDIUM In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.
| Apr 2, 2024 | 5.5 | 21 | NO | NO |
CVE-2024-3900MEDIUM Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
| Apr 17, 2024 | 5.5 | 20 | NO | NO |
CVE-2023-2664MEDIUM In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.
| May 11, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-2663MEDIUM In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.
| May 11, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-2662MEDIUM In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
| May 11, 2023 | 5.5 | 20 | NO | NO |
CVE-2024-7867MEDIUM In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero. | Aug 15, 2024 | 6.2 | 18 | NO | NO |
CVE-2024-7866MEDIUM In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow. | Aug 15, 2024 | 5.5 | 18 | NO | NO |
CVE-2024-4976MEDIUM Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference. | May 15, 2024 | 5.5 | 18 | NO | NO |
CVE-2024-4141MEDIUM Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by mo | Apr 24, 2024 | 5.5 | 18 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA19 CVEs
32%
63%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local18 (94.7%)
Network1 (5.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (78.9%)
High4 (21.1%)
Unknown0 (0.0%)
User Interaction
None11 (57.9%)
Unknown0 (0.0%)
Required8 (42.1%)
Privileges Required
Low5 (26.3%)
High0 (0.0%)
None14 (73.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Glyph & Cog, LLC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Glyph & Cog, LLC as a CNA — matched by CVE ID, not by organization name.