CVE-2025-46205
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD
Description
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.
Affected (1)
Products: Podofo Project: Podofo
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 0.10.0 to 0.10.5 |
References (3)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Timeline
No history available yet.