Tracker Software maintains a focused portfolio of PDF viewing and manipulation tools, including PDF-XChange Viewer and related SDK products, which serve both individual and enterprise users handling document workflows. The identified vulnerabilities cluster around the PDF processing and viewing functionality central to these products. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tracker Software over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5324HIGH Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code | Oct 8, 2012 | 9.3 | 39 | NO | YES |
CVE-2017-13056HIGH The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. | Dec 27, 2017 | 7.8 | 34 | NO | YES |
CVE-2013-0729HIGH Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG imag | Apr 2, 2014 | 9.3 | 25 | NO | NO |
CVE-2018-6462HIGH Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might | Jan 31, 2018 | 7.8 | 24 | NO | NO |
CVE-2010-5245MEDIUM Untrusted search path vulnerability in PDF-XChange Viewer 2.0 Build 54.0 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory | Sep 7, 2012 | 6.9 | 22 | NO | NO |
CVE-2018-18689MEDIUM The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping | Jan 7, 2021 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tracker Software.
Media articles that mention a CVE ID that affects a product developed by Tracker Software — matched by CVE ID, not by vendor name.