flowpaper records
23 published records for vendor flowpaper.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 4.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-476 NULL Pointer Dereference3
- CWE-787 Out-of-bounds Write3
- CWE-416 Use After Free2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2018-11686Proof of concept | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.flowpaper · flexpaper · CWE-20 | Critical9.8 | — | 52.5% | Jul 3, 2019 |
40Plan | CVE-2020-23878No exploit | pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.flowpaper · pdf2json · CWE-787 | Critical9.8 | — | 1.8% | Nov 10, 2021 |
35Monitor | CVE-2018-14947No exploit | An issue has been found in PDF2JSON 0.69.flowpaper · pdf2json · CWE-119 | High8.8 | — | 1.6% | Aug 5, 2018 |
35Monitor | CVE-2018-14946No exploit | An issue has been found in PDF2JSON 0.69.flowpaper · pdf2json · CWE-119 | High8.8 | — | 1.6% | Aug 5, 2018 |
31Monitor | CVE-2020-18750No exploit | Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.flowpaper · pdf2json · CWE-120 | High7.8 | — | 0.5% | Feb 5, 2021 |
30Monitor | CVE-2020-23879No exploit | pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.flowpaper · pdf2json · CWE-476 | High7.5 | — | 1.4% | Nov 10, 2021 |
24Monitor | CVE-2014-9677No exploit | Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web scflowpaper · flexpaper · CWE-79 | Medium6.1 | — | 1.2% | Oct 17, 2017 |
24Monitor | CVE-2014-9678No exploit | FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.flowpaper · flexpaper · CWE-20 | Medium6.1 | — | 1.0% | Oct 17, 2017 |
22Monitor | CVE-2020-19463No exploit | An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.flowpaper · pdf2json · CWE-770 | Medium5.5 | — | 0.7% | Jul 21, 2021 |
22Monitor | CVE-2020-19464No exploit | An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow flowpaper · pdf2json · CWE-770 | Medium5.5 | — | 0.7% | Jul 21, 2021 |
22Monitor | CVE-2020-19474No exploit | An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After flowpaper · pdf2json · CWE-416 | Medium5.5 | — | 0.7% | Jul 21, 2021 |
22Monitor | CVE-2020-19467No exploit | An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to flowpaper · pdf2json · CWE-416 | Medium5.5 | — | 0.7% | Jul 21, 2021 |
22Monitor | CVE-2020-19469No exploit | An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid wflowpaper · pdf2json · CWE-787 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19470No exploit | An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL poiflowpaper · pdf2json · CWE-476 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19471No exploit | An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invflowpaper · pdf2json · CWE-125 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19472No exploit | An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invflowpaper · pdf2json · CWE-125 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19473No exploit | An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncflowpaper · pdf2json · CWE-755 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19475No exploit | An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an iflowpaper · pdf2json · CWE-787 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19468No exploit | An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pflowpaper · pdf2json · CWE-476 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19465No exploit | An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an inflowpaper · pdf2json · CWE-125 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
22Monitor | CVE-2020-19466No exploit | An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to flowpaper · pdf2json · CWE-125 | Medium5.5 | — | 0.6% | Jul 21, 2021 |
21Monitor | CVE-2023-5200No exploit | flowpaper <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeflowpaper · flowpaper · CWE-79 | Medium5.4 | — | 0.5% | Oct 20, 2023 |
21Monitor | CVE-2023-40197No exploit | WordPress flowpaper Plugin <= 1.9.9 is vulnerable to Cross Site Scripting (XSS)flowpaper · flowpaper · CWE-79 | Medium5.4 | — | 0.4% | Sep 4, 2023 |
- CVE-2018-1168655Plan
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.
CriticalCVSS 9.8Proof of conceptEPSS 53%flowpaper · flexpaperJul 3, 2019
- CVE-2020-2387840Plan
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
CriticalCVSS 9.8No exploitEPSS 2%flowpaper · pdf2jsonNov 10, 2021
- CVE-2018-1494735Monitor
An issue has been found in PDF2JSON 0.69.
HighCVSS 8.8No exploitEPSS 2%flowpaper · pdf2jsonAug 5, 2018
- CVE-2018-1494635Monitor
An issue has been found in PDF2JSON 0.69.
HighCVSS 8.8No exploitEPSS 2%flowpaper · pdf2jsonAug 5, 2018
- CVE-2020-1875031Monitor
Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.
HighCVSS 7.8No exploitEPSS 1%flowpaper · pdf2jsonFeb 5, 2021
- CVE-2020-2387930Monitor
pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
HighCVSS 7.5No exploitEPSS 1%flowpaper · pdf2jsonNov 10, 2021
- CVE-2014-967724Monitor
Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web sc
MediumCVSS 6.1No exploitEPSS 1%flowpaper · flexpaperOct 17, 2017
- CVE-2014-967824Monitor
FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.
MediumCVSS 6.1No exploitEPSS 1%flowpaper · flexpaperOct 17, 2017
- CVE-2020-1946322Monitor
An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1946422Monitor
An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1947422Monitor
An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1946722Monitor
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1946922Monitor
An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid w
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1947022Monitor
An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL poi
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1947122Monitor
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an inv
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1947222Monitor
An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an inv
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1947322Monitor
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an unc
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1947522Monitor
An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an i
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1946822Monitor
An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null p
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1946522Monitor
An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an in
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2020-1946622Monitor
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to
MediumCVSS 5.5No exploitEPSS 1%flowpaper · pdf2jsonJul 21, 2021
- CVE-2023-520021Monitor
flowpaper <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 1%flowpaper · flowpaperOct 20, 2023
- CVE-2023-4019721Monitor
WordPress flowpaper Plugin <= 1.9.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%flowpaper · flowpaperSep 4, 2023