Podofo
Vendor:
First CVE: Mar 1, 2017 · Active for 9 years
63
Total CVEs
More Total CVEs than 99% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Podofo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2017
9 years ago
Most Recent CVE
Oct 1, 2025
300 days ago
CVE Severity & Scoring
Podofo63 CVEs
65%
30%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local44 (69.8%)
Network19 (30.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (7.9%)
Unknown0 (0.0%)
Required58 (92.1%)
Privileges Required
Low2 (3.2%)
High0 (0.0%)
None61 (96.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8002HIGH In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers cou | Mar 9, 2018 | 8.8 | 42 | NO | YES |
CVE-2017-8378CRITICAL Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or | May 1, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-8000HIGH In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attac | Mar 9, 2018 | 8.8 | 29 | NO | NO |
CVE-2025-46205HIGH A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. | Oct 1, 2025 | 8.1 | 27 | NO | NO |
CVE-2023-31568HIGH Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. | May 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-31567HIGH Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. | May 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-31566HIGH Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted(). | May 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-19532HIGH A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by p | Nov 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-8787HIGH The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service ( | May 5, 2017 | 8.8 | 27 | NO | NO |
CVE-2018-20751HIGH An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the | Feb 4, 2019 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (63 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (63 CVEs).
Media Mentions
Signals from CVEs in this product scope (63 CVEs).
Top CNAs Publishing CVEs For Podofo
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.1.0 | 1 | 5.5 | 0.2% | 0 | 0 |
| 0.9.7 | 4 | 6.1 | 0.7% | 0 | 0 |
| 0.9.6 | 11 | 7.1 | 1.4% | 0 | 0 |
| 0.9.5 | 27 | 6.3 | 1.6% | 0 | 1 |
| 0.9.4 | 11 | 6.3 | 1.4% | 0 | 0 |
| 0.10.0 | 6 | 7.9 | 0.7% | 0 | 0 |