Pdf-Xchange Editor vulnerabilities

289 known vulnerabilities affecting pdf-xchange/pdf-xchange_editor.

Total CVEs
289
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH166MEDIUM106LOW17

Vulnerabilities

Page 11 of 15
CVE-2022-37362HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37362 [HIGH] CWE-787 CVE-2022-37362: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a writ
cvelistv5nvd
CVE-2022-37356HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37356 [HIGH] CWE-787 CVE-2022-37356: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted data in a JPG file can trigger a writ
cvelistv5nvd
CVE-2022-37374HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37374 [HIGH] CWE-416 CVE-2022-37374: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of validating
cvelistv5nvd
CVE-2022-37364HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37364 [HIGH] CWE-787 CVE-2022-37364: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a wri
cvelistv5nvd
CVE-2022-37371HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37371 [HIGH] CWE-787 CVE-2022-37371: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a writ
cvelistv5nvd
CVE-2022-37372HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37372 [HIGH] CWE-787 CVE-2022-37372: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a writ
cvelistv5nvd
CVE-2022-37369HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37369 [HIGH] CWE-787 CVE-2022-37369: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a writ
cvelistv5nvd
CVE-2022-37355HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37355 [HIGH] CWE-787 CVE-2022-37355: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. Crafted data in a JPG file can trigger a writ
cvelistv5nvd
CVE-2022-37367HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37367 [HIGH] CWE-125 CVE-2022-37367: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. Crafted data in an AcroForm can trigger a re
cvelistv5nvd
CVE-2022-37349HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37349 [HIGH] CWE-125 CVE-2022-37349: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the submitForm method. By performing actions in JavaScript, an attacker
cvelistv5nvd
CVE-2022-37366HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37366 [HIGH] CWE-125 CVE-2022-37366: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an at
cvelistv5nvd
CVE-2022-37353MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37353 [MEDIUM] CWE-125 CVE-2022-37353: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can tri
cvelistv5nvd
CVE-2022-37360MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37360 [MEDIUM] CWE-125 CVE-2022-37360: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can tri
cvelistv5nvd
CVE-2022-37351MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37351 [MEDIUM] CWE-125 CVE-2022-37351: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K files. Crafted data in a J2K file can trig
cvelistv5nvd
CVE-2022-37352MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37352 [MEDIUM] CWE-125 CVE-2022-37352: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of WMF files. Crafted data in a WMF file can trig
cvelistv5nvd
CVE-2022-37368MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37368 [MEDIUM] CWE-125 CVE-2022-37368: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScr
cvelistv5nvd
CVE-2022-37361MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37361 [MEDIUM] CWE-125 CVE-2022-37361: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. Crafted data in a JP2 file can trig
cvelistv5nvd
CVE-2022-37370MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37370 [MEDIUM] CWE-125 CVE-2022-37370: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trig
cvelistv5nvd
CVE-2022-37375MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37375 [MEDIUM] CWE-125 CVE-2022-37375: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPC files. Crafted data in a JPC file can trig
cvelistv5nvd
CVE-2022-37373MEDIUMCVSS 5.5v9.3.361.02023-03-29
CVE-2022-37373 [MEDIUM] CWE-125 CVE-2022-37373: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trig
cvelistv5nvd