Записи itextpdf
8 опубликованных записей вендора itextpdf.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-129 Improper Validation of Array Index1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-125 Out-of-bounds Read1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2021-43113Эксплойта нет | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (itextpdf · itext · CWE-77 | Критическая9,8 | — | 5,2 % | 15 дек. 2021 г. |
39Наблюдать | CVE-2017-20151Эксплойта нет | iText RUPS XfaFile.java xml external entity referenceitextpdf · rups · CWE-611 | Критическая9,8 | — | 0,8 % | 30 дек. 2022 г. |
38Наблюдать | CVE-2017-9096Proof of concept | The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct itextpdf · itext · CWE-611 | Высокая8,8 | — | 9,6 % | 8 нояб. 2017 г. |
26Наблюдать | CVE-2022-24196Эксплойта нет | iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, whitextpdf · itext · CWE-770 | Средняя6,5 | — | 1,6 % | 1 февр. 2022 г. |
26Наблюдать | CVE-2022-24197Эксплойта нет | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause aitextpdf · itext · CWE-787 | Средняя6,5 | — | 1,5 % | 1 февр. 2022 г. |
26Наблюдать | CVE-2023-6298Эксплойта нет | Apryse iText PdfDocument.java main array indexitextpdf · itext · CWE-129 | Средняя6,5 | — | 1,1 % | 26 нояб. 2023 г. |
26Наблюдать | CVE-2023-6299Эксплойта нет | Apryse iText Reference Table PdfDocument.java memory leakitextpdf · itext · CWE-401 | Средняя6,5 | — | 0,9 % | 26 нояб. 2023 г. |
26Наблюдать | CVE-2022-24198Эксплойта нет | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackeritextpdf · itext · CWE-125 | Средняя6,5 | — | 0,5 % | 1 февр. 2022 г. |
- CVE-2021-4311341В плане
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %itextpdf · itext15 дек. 2021 г.
- CVE-2017-2015139Наблюдать
iText RUPS XfaFile.java xml external entity reference
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %itextpdf · rups30 дек. 2022 г.
- CVE-2017-909638Наблюдать
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %itextpdf · itext8 нояб. 2017 г.
- CVE-2022-2419626Наблюдать
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, wh
СредняяCVSS 6,5Эксплойта нетEPSS 2 %itextpdf · itext1 февр. 2022 г.
- CVE-2022-2419726Наблюдать
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a
СредняяCVSS 6,5Эксплойта нетEPSS 2 %itextpdf · itext1 февр. 2022 г.
- CVE-2023-629826Наблюдать
Apryse iText PdfDocument.java main array index
СредняяCVSS 6,5Эксплойта нетEPSS 1 %itextpdf · itext26 нояб. 2023 г.
- CVE-2023-629926Наблюдать
Apryse iText Reference Table PdfDocument.java memory leak
СредняяCVSS 6,5Эксплойта нетEPSS 1 %itextpdf · itext26 нояб. 2023 г.
- CVE-2022-2419826Наблюдать
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attacker
СредняяCVSS 6,5Эксплойта нетEPSS 1 %itextpdf · itext1 февр. 2022 г.