Verypdf develops a narrowly scoped suite of PDF processing and viewing tools, with reported vulnerabilities concentrating in its core PDF manipulation products and the Encrypt PDF utility. The durable signal reflects memory-safety issues endemic to PDF parsing, centered on buffer-boundary violations and out-of-bounds writes that arise from handling untrusted document structures. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verypdf over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5492HIGH Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code v | Dec 12, 2008 | 9.3 | 61 | NO | YES |
CVE-2019-11493HIGH VeryPDF 4.1 has a Memory Overflow leading to Code Execution because pdfocx!CxImageTIF::operator in pdfocx.ocx (used by pdfeditor.exe and pdfcmd.exe) is mishandled. | Apr 26, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-25550MEDIUM Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers | Mar 21, 2026 | 6.2 | 21 | NO | NO |
CVE-2019-25549MEDIUM VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attacker | Mar 21, 2026 | 6.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verypdf.
Media articles that mention a CVE ID that affects a product developed by Verypdf — matched by CVE ID, not by vendor name.