Skip to content
Noroxi

itextpdf records

8 published records for vendor itextpdf.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
75%
Median publish → KEV
No record has entered KEV

All records

8 records
  • iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (

    CriticalCVSS 9.8No exploitEPSS 5%

    itextpdf · itextDec 15, 2021

  • iText RUPS XfaFile.java xml external entity reference

    CriticalCVSS 9.8No exploitEPSS 1%

    itextpdf · rupsDec 30, 2022

  • CVE-2017-9096
    38Monitor

    The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct

    HighCVSS 8.8Proof of conceptEPSS 10%

    itextpdf · itextNov 8, 2017

  • iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, wh

    MediumCVSS 6.5No exploitEPSS 2%

    itextpdf · itextFeb 1, 2022

  • iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a

    MediumCVSS 6.5No exploitEPSS 2%

    itextpdf · itextFeb 1, 2022

  • CVE-2023-6298
    26Monitor

    Apryse iText PdfDocument.java main array index

    MediumCVSS 6.5No exploitEPSS 1%

    itextpdf · itextNov 26, 2023

  • CVE-2023-6299
    26Monitor

    Apryse iText Reference Table PdfDocument.java memory leak

    MediumCVSS 6.5No exploitEPSS 1%

    itextpdf · itextNov 26, 2023

  • iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attacker

    MediumCVSS 6.5No exploitEPSS 1%

    itextpdf · itextFeb 1, 2022