CVE-2018-7264 describes multiple out-of-bounds write and sign errors within the Pictview image processing library, which is embedded in the ActivePDF Toolkit up to version 2018.1.0.18321. This critical vulnerability (CVSS 9.8) allows a remote, unauthenticated attacker to execute arbitrary code on vulnerable applications by processing specially crafted, untrusted images. While there is no evidence of active exploitation (KEV: No), public exploit code (EDB-44251) exists, and its EPSS score indicates a higher than average likelihood of exploitation, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.1.0.19023CPE matchmatch criteria | cpe:2.3:a:activepdf:activepdf_toolkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.