CVE-2010-0207 describes a denial-of-service vulnerability in xpdf and xpdf-based PDF viewers, including those in Debian Linux. A remote attacker can trigger an infinite loop in the xref table of a malicious PDF, causing the application to crash. Rated Medium severity (CVSS 5.5), this vulnerability requires user interaction (opening a crafted PDF) and has a high impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this decade-old flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.03-17CPE matchmatch criteria | cpe:2.3:a:xpdfreader:xpdf:3.03-17:*:*:*:*:*:*:* | ||
3.04-4CPE matchmatch criteria | cpe:2.3:a:xpdfreader:xpdf:3.04-4:*:*:*:*:*:*:* | ||
3.04-13CPE matchmatch criteria | cpe:2.3:a:xpdfreader:xpdf:3.04-13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.