Pdfalto Project maintains a specialized PDF-processing utility with a focused vulnerability footprint centered on memory-safety issues during file parsing, particularly out-of-bounds read and write conditions that arise in the handling of malformed or adversarially crafted PDF structures. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdfalto Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32324CRITICAL PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc. | Jul 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2018-17338HIGH An issue has been found in pdfalto through 0.2. It is a heap-based buffer overflow in the function TextPage::dump in XmlAltoOutputDev.cc. | Sep 23, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-18274HIGH A issue was found in pdfalto 0.2. There is a heap-based buffer overflow in the TextPage::addAttributsNode function in XmlAltoOutputDev.cc. | Oct 12, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-9878HIGH There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for e | Mar 21, 2019 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdfalto Project.
Media articles that mention a CVE ID that affects a product developed by Pdfalto Project — matched by CVE ID, not by vendor name.