CVE-2017-2814 is a heap overflow vulnerability in Poppler 0.53.0's image rendering functionality, affecting freedesktop Poppler. A specially crafted PDF can trigger heap corruption through image resizing after allocation, potentially leading to arbitrary code execution. With a CVSS score of 8.8 (High), it presents a significant risk as it can be exploited remotely with low attack complexity, requiring user interaction. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it is not listed in CISA's KEV catalog, its high FAUCET Risk Score of 72/100 indicates a notable threat. There is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.53.0CPE matchmatch criteria | cpe:2.3:a:freedesktop:poppler:0.53.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.