Libextractor is a focused metadata-extraction library that, despite a narrow product scope, sees integration across document-processing and indexing applications where it handles untrusted file inputs. The vendor's disclosures cluster around parsing and data-handling challenges inherent to supporting diverse file formats; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libextractor over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3625HIGH Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t | Dec 31, 2005 | 10.0 | 26 | NO | NO |
CVE-2006-2458MEDIUM Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plu | May 18, 2006 | 4.0 | 23 | NO | YES |
CVE-2006-1244HIGH Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unk | Mar 15, 2006 | 7.6 | 20 | NO | NO |
CVE-2005-3626MEDIUM Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDe | Dec 31, 2005 | 5.0 | 16 | NO | NO |
CVE-2005-3624MEDIUM The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via ne | Dec 31, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libextractor.
Media articles that mention a CVE ID that affects a product developed by Libextractor — matched by CVE ID, not by vendor name.