5.5

CVE-2021-27906

A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

Data is provided by the National Vulnerability Database (NVD)
ApachePdfbox Version >= 2.0.0 <= 2.0.22
FedoraprojectFedora Version32
FedoraprojectFedora Version33
FedoraprojectFedora Version34
OracleCommunications Session Report Manager Version >= 8.0.0 <= 8.2.4.0
OracleFlexcube Universal Banking Version >= 14.0.0 <= 14.3.0
OracleHyperion Financial Reporting Version11.1.2.4
OracleHyperion Financial Reporting Version11.2.6.0
OracleOutside In Technology Version8.5.5
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleWebcenter Sites Version12.2.1.3.0
OracleWebcenter Sites Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.54% 0.668
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.