CVE-2023-6298
- EPSS 0.05%
- Veröffentlicht 26.11.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:33
A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. ...
CVE-2023-6299
- EPSS 0.06%
- Veröffentlicht 26.11.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:33
A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component Reference Table Handler. The manipulation leads to memory leak. The a...
CVE-2022-24196
- EPSS 0.55%
- Veröffentlicht 01.02.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:59
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-24197
- EPSS 0.55%
- Veröffentlicht 01.02.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:59
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-24198
- EPSS 0.49%
- Veröffentlicht 01.02.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:59
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerabilit...
CVE-2021-43113
- EPSS 2.18%
- Veröffentlicht 15.12.2021 07:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:41
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
CVE-2017-9096
- EPSS 9.69%
- Veröffentlicht 08.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.