Podofo

Vendor:

First CVE: Mar 1, 2017 · Active for 9 years

63
Total CVEs
More Total CVEs than 99% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Podofo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2017
9 years ago
Most Recent CVE
Oct 1, 2025
300 days ago

CVE Severity & Scoring

Podofo63 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local44 (69.8%)
Network19 (30.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (7.9%)
Unknown0 (0.0%)
Required58 (92.1%)
Privileges Required
Low2 (3.2%)
High0 (0.0%)
None61 (96.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers cou
Mar 9, 20188.842NOYES
Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or
May 1, 20179.831NONO
In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attac
Mar 9, 20188.829NONO
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file.
Oct 1, 20258.127NONO
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.
May 10, 20238.827NONO
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.
May 10, 20238.827NONO
Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted().
May 10, 20238.827NONO
A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by p
Nov 26, 20188.827NONO
The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (
May 5, 20178.827NONO
An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the
Feb 4, 20198.826NONO

Exploit Exposure

Signals from CVEs in this product scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (63 CVEs).

Media Mentions

Signals from CVEs in this product scope (63 CVEs).

Top CNAs Publishing CVEs For Podofo

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1.015.50.2%00
0.9.746.10.7%00
0.9.6117.11.4%00
0.9.5276.31.6%01
0.9.4116.31.4%00
0.10.067.90.7%00