itextpdf records
8 published records for vendor itextpdf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-129 Improper Validation of Array Index1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-125 Out-of-bounds Read1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2021-43113No exploit | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (itextpdf · itext · CWE-77 | Critical9.8 | — | 5.2% | Dec 15, 2021 |
39Monitor | CVE-2017-20151No exploit | iText RUPS XfaFile.java xml external entity referenceitextpdf · rups · CWE-611 | Critical9.8 | — | 0.8% | Dec 30, 2022 |
38Monitor | CVE-2017-9096Proof of concept | The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct itextpdf · itext · CWE-611 | High8.8 | — | 9.6% | Nov 8, 2017 |
26Monitor | CVE-2022-24196No exploit | iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, whitextpdf · itext · CWE-770 | Medium6.5 | — | 1.6% | Feb 1, 2022 |
26Monitor | CVE-2022-24197No exploit | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause aitextpdf · itext · CWE-787 | Medium6.5 | — | 1.5% | Feb 1, 2022 |
26Monitor | CVE-2023-6298No exploit | Apryse iText PdfDocument.java main array indexitextpdf · itext · CWE-129 | Medium6.5 | — | 1.1% | Nov 26, 2023 |
26Monitor | CVE-2023-6299No exploit | Apryse iText Reference Table PdfDocument.java memory leakitextpdf · itext · CWE-401 | Medium6.5 | — | 0.9% | Nov 26, 2023 |
26Monitor | CVE-2022-24198No exploit | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackeritextpdf · itext · CWE-125 | Medium6.5 | — | 0.5% | Feb 1, 2022 |
- CVE-2021-4311341Plan
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (
CriticalCVSS 9.8No exploitEPSS 5%itextpdf · itextDec 15, 2021
- CVE-2017-2015139Monitor
iText RUPS XfaFile.java xml external entity reference
CriticalCVSS 9.8No exploitEPSS 1%itextpdf · rupsDec 30, 2022
- CVE-2017-909638Monitor
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct
HighCVSS 8.8Proof of conceptEPSS 10%itextpdf · itextNov 8, 2017
- CVE-2022-2419626Monitor
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, wh
MediumCVSS 6.5No exploitEPSS 2%itextpdf · itextFeb 1, 2022
- CVE-2022-2419726Monitor
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a
MediumCVSS 6.5No exploitEPSS 2%itextpdf · itextFeb 1, 2022
- CVE-2023-629826Monitor
Apryse iText PdfDocument.java main array index
MediumCVSS 6.5No exploitEPSS 1%itextpdf · itextNov 26, 2023
- CVE-2023-629926Monitor
Apryse iText Reference Table PdfDocument.java memory leak
MediumCVSS 6.5No exploitEPSS 1%itextpdf · itextNov 26, 2023
- CVE-2022-2419826Monitor
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attacker
MediumCVSS 6.5No exploitEPSS 1%itextpdf · itextFeb 1, 2022