Skip to content
Noroxi

flowpaper records

23 published records for vendor flowpaper.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
4.3%
Median publish → KEV
No record has entered KEV

All records

23 records
  • The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

    CriticalCVSS 9.8Proof of conceptEPSS 53%

    flowpaper · flexpaperJul 3, 2019

  • pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.

    CriticalCVSS 9.8No exploitEPSS 2%

    flowpaper · pdf2jsonNov 10, 2021

  • An issue has been found in PDF2JSON 0.69.

    HighCVSS 8.8No exploitEPSS 2%

    flowpaper · pdf2jsonAug 5, 2018

  • An issue has been found in PDF2JSON 0.69.

    HighCVSS 8.8No exploitEPSS 2%

    flowpaper · pdf2jsonAug 5, 2018

  • Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.

    HighCVSS 7.8No exploitEPSS 1%

    flowpaper · pdf2jsonFeb 5, 2021

  • pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.

    HighCVSS 7.5No exploitEPSS 1%

    flowpaper · pdf2jsonNov 10, 2021

  • CVE-2014-9677
    24Monitor

    Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web sc

    MediumCVSS 6.1No exploitEPSS 1%

    flowpaper · flexpaperOct 17, 2017

  • CVE-2014-9678
    24Monitor

    FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    flowpaper · flexpaperOct 17, 2017

  • An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid w

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL poi

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an inv

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an inv

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an unc

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an i

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null p

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an in

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to

    MediumCVSS 5.5No exploitEPSS 1%

    flowpaper · pdf2jsonJul 21, 2021

  • CVE-2023-5200
    21Monitor

    flowpaper <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    flowpaper · flowpaperOct 20, 2023

  • WordPress flowpaper Plugin <= 1.9.9 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    flowpaper · flowpaperSep 4, 2023