Aspose offers a narrow line of document-processing and office-format conversion libraries for .NET and C/C++ environments, used to programmatically generate and manipulate PDFs, spreadsheets, and word documents. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through memory-safety weakness classes including use-after-free, out-of-bounds read and write conditions, stack-based buffer overflows, and use of uninitialized resources, reflecting the parsing and format-handling complexity inherent to these libraries. Defenders should treat Aspose library updates as a remediation priority in environments where untrusted documents are processed; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aspose over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5067CRITICAL An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write fr | Sep 18, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-5066CRITICAL An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap poi | Sep 18, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-5041HIGH An exploitable Stack Based Buffer Overflow vulnerability exists in the EnumMetaInfo function of Aspose Aspose.Words library, version 18.11.0.0. A specially crafted doc file can cau | Aug 21, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5042HIGH An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling hea | Sep 18, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-5033HIGH An exploitable out-of-bounds read vulnerability exists in the Number record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds re | Aug 21, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5032HIGH An exploitable out-of-bounds read vulnerability exists in the LabelSst record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds | Aug 21, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aspose.
Media articles that mention a CVE ID that affects a product developed by Aspose — matched by CVE ID, not by vendor name.