PDF Resurrect is a specialized tool for analyzing and recovering content from PDF documents, with a narrow but focused vulnerability footprint concentrated in its core product. The observed weakness classes—out-of-bounds writes and infinite loops—reflect the parsing and state-management complexity inherent to processing potentially malformed or adversarially constructed PDF files. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdfresurrect Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14267HIGH PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled. | Jul 29, 2019 | 7.8 | 39 | NO | YES |
CVE-2020-9549HIGH In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document. | Mar 2, 2020 | 7.8 | 26 | NO | NO |
CVE-2019-14934HIGH An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write. | Aug 11, 2019 | 7.8 | 25 | NO | NO |
CVE-2020-20740HIGH PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version(). | Nov 20, 2020 | 7.8 | 24 | NO | NO |
CVE-2021-3508MEDIUM A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a crafted PDF file. | Apr 28, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdfresurrect Project.
Media articles that mention a CVE ID that affects a product developed by Pdfresurrect Project — matched by CVE ID, not by vendor name.