Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xpdf Project

First CVE: Oct 20, 2000Active for: 26 yearsTotal CVEs: 131
40.9
VTI Score
High

Xpdf Project maintains a lightweight, open-source PDF parser that has remained prominent in the vulnerability landscape despite its narrow product scope, reflecting its wide adoption in embedded and specialized applications. The vendor's vulnerability exposure recurs consistently around memory-safety and validation weaknesses—out-of-bounds writes, buffer overflows, improper exception handling, and incorrect comparisons—that are characteristic of C-based parsing code operating on untrusted document inputs. Defenders should treat Xpdf updates as relevant to any application or embedded system that bundles this parser, since remediation often depends on downstream vendors; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
121
Total CVEs
More Total CVEs than 92% of tracked vendors
8.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.8%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xpdf Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Oct 16, 2025
281 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (121 CVEs).

121 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-30860HIGH
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
CVE-2003-0434HIGH
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Jul 24, 20037.557NOYES
CVE-2004-0888HIGH
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras
Jan 27, 200510.034NONO
CVE-2004-0889HIGH
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra
Jan 27, 200510.033NONO
CVE-2004-1125HIGH
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows
Jan 10, 20059.331NONO
CVE-2012-2142HIGH
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
Jan 9, 20207.826NONO
CVE-2010-3702HIGH
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows con
Nov 5, 20107.526NONO
CVE-2005-3625HIGH
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t
Dec 31, 200510.026NONO
CVE-2021-36493HIGH
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
Feb 3, 20237.525NONO
CVE-2022-38928HIGH
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
Sep 21, 20227.825NONO
View all 121 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products121 CVEs
60%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local90 (74.4%)
Network3 (2.5%)
Unknown28 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low91 (75.2%)
High2 (1.7%)
Unknown28 (23.1%)
User Interaction
None12 (9.9%)
Unknown28 (23.1%)
Required81 (66.9%)
Privileges Required
Low6 (5.0%)
High0 (0.0%)
None87 (71.9%)
Unknown28 (23.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (121 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.8% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xpdf Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xpdf Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xpdf Project's Products

View all 5 CNAs →

Top CWEs