CVE-2025-9394 is a use-after-free vulnerability in PoDoFo 1.1.0-dev, specifically within the PdfTokenizer::DetermineDataType function, affecting the PDF Dictionary Parser component. This flaw carries a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local user privileges, and leading to high availability impact. While an exploit has been published, there is no evidence of active exploitation, and it lacks coverage in common exploit databases or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0CPE matchmatch criteria | cpe:2.3:a:podofo_project:podofo:1.1.0:dev:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.