Qpdf

Vendor:

First CVE: May 23, 2017 · Active for 9 years

19
Total CVEs
More Total CVEs than 95% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Qpdf over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2017
9 years ago
Most Recent CVE
Feb 29, 2024
879 days ago

CVE Severity & Scoring

Qpdf19 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local18 (94.7%)
Network1 (5.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required19 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhausti
Apr 10, 20187.825NONO
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation faul
Aug 27, 20177.824NONO
QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a
Jul 22, 20226.522NONO
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain do
Jul 20, 20215.520NONO
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function
Jul 25, 20175.520NONO
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveL
Jul 25, 20175.520NONO
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInS
Jul 25, 20175.520NONO
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, ak
May 23, 20175.520NONO
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::par
May 23, 20175.520NONO
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved funct
May 23, 20175.520NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Qpdf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.4.216.50.7%00
8.2.113.31.3%00
7.0.b117.81.8%00
6.0.085.81.4%00
11.9.015.50.4%00
10.0.415.30.5%00