← Back

Pdfreactor

pdfreactor

Vendor: Realobjects • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Realobjects
1Pdfreactor
Nov 21, 2024
Jun 11, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of...Show more
XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions.Show less
1Realobjects
1Pdfreactor
Nov 21, 2024
Jun 11, 2019
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.