Pdftools Project maintains a narrowly scoped PDF-processing library that, despite limited product breadth, serves as a foundational component across many document-handling systems and applications. Its vulnerability profile centers on memory-safety issues, particularly NULL-pointer dereferences and out-of-bounds writes, which reflect the low-level parsing demands of PDF file format handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdftools Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39540HIGH An issue was discovered in pdftools through 20200714. A stack-buffer-overflow exists in the function Analyze::AnalyzePages() located in analyze.cpp. It allows an attacker to cause | Sep 20, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-39543MEDIUM An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeRoot() located in analyze.cpp. It allows an attacker to caus | Sep 20, 2021 | 5.5 | 19 | NO | NO |
CVE-2021-39542MEDIUM An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Font::Size() located in font.cpp. It allows an attacker to cause Denial of S | Sep 20, 2021 | 5.5 | 19 | NO | NO |
CVE-2021-39541MEDIUM An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeXref() located in analyze.cpp. It allows an attacker to caus | Sep 20, 2021 | 5.5 | 19 | NO | NO |
CVE-2021-39539MEDIUM An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::BDCNode::~BDCNode() located in bdcnode.cpp. It allows an attacker to c | Sep 20, 2021 | 5.5 | 19 | NO | NO |
CVE-2021-39538MEDIUM An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::ObjNode::Value() located in objnode.cpp. It allows an attacker to caus | Sep 20, 2021 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdftools Project.
Media articles that mention a CVE ID that affects a product developed by Pdftools Project — matched by CVE ID, not by vendor name.