cbcvebase.
CVE-2023-1709
published 2023-06-07

CVE-2023-1709: Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an…

PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.26%
17.5th percentile
Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.

Affected

9 ranges
VendorProductVersion rangeFixed in
datalogicslibrary_apdfl<= v18.0.4PlusP1e
siemensjt2go< 14.2.0.214.2.0.2
siemensteamcenter_visualization>= 13.2 < 13.2.0.1313.2.0.13
siemensteamcenter_visualization>= 13.2.0 < 13.2.0.1313.2.0.13
siemensteamcenter_visualization>= 13.3 < 13.3.0.913.3.0.9
siemensteamcenter_visualization>= 13.3.0 < 13.3.0.913.3.0.9
siemensteamcenter_visualization>= 14.0 < 14.0.0.514.0.0.5
siemensteamcenter_visualization>= 14.1 < 14.1.0.714.1.0.7
siemensteamcenter_visualization>= 14.2 < 14.2.0.214.2.0.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.