Itextpdf

Itext

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Published 26.11.2023 23:15:07
  • Last modified 21.11.2024 08:43:33

A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. ...

  • EPSS 0.06%
  • Published 26.11.2023 23:15:07
  • Last modified 21.11.2024 08:43:33

A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component Reference Table Handler. The manipulation leads to memory leak. The a...

Exploit
  • EPSS 0.55%
  • Published 01.02.2022 20:15:11
  • Last modified 21.11.2024 06:49:59

iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

Exploit
  • EPSS 0.55%
  • Published 01.02.2022 20:15:11
  • Last modified 21.11.2024 06:49:59

iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

  • EPSS 0.49%
  • Published 01.02.2022 20:15:11
  • Last modified 21.11.2024 06:49:59

iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerabilit...

Exploit
  • EPSS 2.18%
  • Published 15.12.2021 07:15:07
  • Last modified 21.11.2024 06:28:41

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

  • EPSS 9.69%
  • Published 08.11.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.