itextpdf kayıtları
itextpdf üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-129 Improper Validation of Array Index1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-125 Out-of-bounds Read1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2021-43113İstismar yok | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (itextpdf · itext · CWE-77 | Kritik9,8 | — | %5,2 | 15 Ara 2021 |
39İzleyin | CVE-2017-20151İstismar yok | iText RUPS XfaFile.java xml external entity referenceitextpdf · rups · CWE-611 | Kritik9,8 | — | %0,8 | 30 Ara 2022 |
38İzleyin | CVE-2017-9096Kavram kanıtı | The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct itextpdf · itext · CWE-611 | Yüksek8,8 | — | %9,6 | 8 Kas 2017 |
26İzleyin | CVE-2022-24196İstismar yok | iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, whitextpdf · itext · CWE-770 | Orta6,5 | — | %1,6 | 1 Şub 2022 |
26İzleyin | CVE-2022-24197İstismar yok | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause aitextpdf · itext · CWE-787 | Orta6,5 | — | %1,5 | 1 Şub 2022 |
26İzleyin | CVE-2023-6298İstismar yok | Apryse iText PdfDocument.java main array indexitextpdf · itext · CWE-129 | Orta6,5 | — | %1,1 | 26 Kas 2023 |
26İzleyin | CVE-2023-6299İstismar yok | Apryse iText Reference Table PdfDocument.java memory leakitextpdf · itext · CWE-401 | Orta6,5 | — | %0,9 | 26 Kas 2023 |
26İzleyin | CVE-2022-24198İstismar yok | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackeritextpdf · itext · CWE-125 | Orta6,5 | — | %0,5 | 1 Şub 2022 |
- CVE-2021-4311341Planlayın
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (
KritikCVSS 9,8İstismar yokEPSS %5itextpdf · itext15 Ara 2021
- CVE-2017-2015139İzleyin
iText RUPS XfaFile.java xml external entity reference
KritikCVSS 9,8İstismar yokEPSS %1itextpdf · rups30 Ara 2022
- CVE-2017-909638İzleyin
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct
YüksekCVSS 8,8Kavram kanıtıEPSS %10itextpdf · itext8 Kas 2017
- CVE-2022-2419626İzleyin
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, wh
OrtaCVSS 6,5İstismar yokEPSS %2itextpdf · itext1 Şub 2022
- CVE-2022-2419726İzleyin
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a
OrtaCVSS 6,5İstismar yokEPSS %2itextpdf · itext1 Şub 2022
- CVE-2023-629826İzleyin
Apryse iText PdfDocument.java main array index
OrtaCVSS 6,5İstismar yokEPSS %1itextpdf · itext26 Kas 2023
- CVE-2023-629926İzleyin
Apryse iText Reference Table PdfDocument.java memory leak
OrtaCVSS 6,5İstismar yokEPSS %1itextpdf · itext26 Kas 2023
- CVE-2022-2419826İzleyin
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attacker
OrtaCVSS 6,5İstismar yokEPSS %1itextpdf · itext1 Şub 2022