Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Podofo Project

First CVE: Mar 1, 2017Active for: 9 yearsTotal CVEs: 63
38.3
VTI Score
Medium

Podofo is a lightweight open-source PDF manipulation library embedded across document-processing applications and tools, giving its vulnerability footprint broader downstream relevance than its single-product scope might suggest. The vendor's disclosures cluster around memory-safety and bounds-checking weaknesses—null-pointer dereferences, out-of-bounds reads and writes, and infinite-loop conditions—reflecting the parsing complexity inherent to PDF format handling and the demands of a C++-based codebase operating on untrusted input. These weakness classes are characteristic of low-level document processors and can surface across any application that integrates the library, making remediation dependent on downstream vendors rebuilding and redistributing. Defenders should inventory applications that bundle Podofo rather than the library alone, monitor vendor releases for parser-related fixes, and treat PDF processing from untrusted sources as a potential exposure vector; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
63
Total CVEs
More Total CVEs than 99% of tracked vendors
10.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Podofo Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2017
9 years ago
Most Recent CVE
Oct 1, 2025
296 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-8002HIGH
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers cou
Mar 9, 20188.842NOYES
CVE-2017-8378CRITICAL
Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or
May 1, 20179.831NONO
CVE-2018-8000HIGH
In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attac
Mar 9, 20188.829NONO
CVE-2025-46205HIGH
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file.
Oct 1, 20258.127NONO
CVE-2023-31568HIGH
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
May 10, 20238.827NONO
CVE-2023-31567HIGH
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.
May 10, 20238.827NONO
CVE-2023-31566HIGH
Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().
May 10, 20238.827NONO
CVE-2018-19532HIGH
A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by p
Nov 26, 20188.827NONO
CVE-2017-8787HIGH
The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (
May 5, 20178.827NONO
CVE-2018-20751HIGH
An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the
Feb 4, 20198.826NONO
View all 63 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products63 CVEs
65%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local44 (69.8%)
Network19 (30.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (7.9%)
Unknown0 (0.0%)
Required58 (92.1%)
Privileges Required
Low2 (3.2%)
High0 (0.0%)
None61 (96.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Podofo Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Podofo Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Podofo Project's Products

View all 5 CNAs →

Top CWEs