← Back

CVE-2025-46205

nvd nist
Published: Oct 1, 2025Modified: Oct 27, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.

Affected (1)

Podofo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.10.0 to 0.10.5

References (3)

Timeline

No history available yet.