Pdf-Xchange Editor vulnerabilities
289 known vulnerabilities affecting pdf-xchange/pdf-xchange_editor.
Total CVEs
289
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH166MEDIUM106LOW17
Vulnerabilities
Page 13 of 15
CVE-2024-27324P4MEDIUMCVSS 5.5≥ 10.1.1.381, < 10.1.3.383v10.1.1.3812024-04-01
CVE-2024-27324 [MEDIUM] CWE-125 CVE-2024-27324: PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vu
PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
nvd
CVE-2024-27326P4MEDIUMCVSS 5.5v10.1.1.3812024-04-01
CVE-2024-27326 [MEDIUM] CWE-125 CVE-2024-27326: PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vu
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
nvd
CVE-2024-27329P4MEDIUMCVSS 5.5v10.1.1.3812024-04-01
CVE-2024-27329 [MEDIUM] CWE-125 CVE-2024-27329: PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vu
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
nvd
CVE-2023-39505P4MEDIUMCVSS 5.5v9.5.366.02024-05-03
CVE-2023-39505 [MEDIUM] CWE-749 CVE-2023-39505: PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability
PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio
nvd
CVE-2023-39495P4MEDIUMCVSS 5.5v9.5.366.02024-05-03
CVE-2023-39495 [MEDIUM] CWE-749 CVE-2023-39495: PDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure Vulnerabilit
PDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malici
nvd
CVE-2022-42407P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42407 [MEDIUM] CWE-125 CVE-2022-42407: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can tri
nvd
CVE-2022-42384P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42384 [MEDIUM] CWE-125 CVE-2022-42384: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42406P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42406 [MEDIUM] CWE-125 CVE-2022-42406: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can tri
nvd
CVE-2022-42385P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42385 [MEDIUM] CWE-125 CVE-2022-42385: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42398P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42398 [MEDIUM] CWE-125 CVE-2022-42398: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trig
nvd
CVE-2022-42390P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42390 [MEDIUM] CWE-125 CVE-2022-42390: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42392P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42392 [MEDIUM] CWE-125 CVE-2022-42392: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42389P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42389 [MEDIUM] CWE-125 CVE-2022-42389: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42391P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42391 [MEDIUM] CWE-125 CVE-2022-42391: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42375P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42375 [MEDIUM] CWE-125 CVE-2022-42375: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42388P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42388 [MEDIUM] CWE-125 CVE-2022-42388: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42393P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42393 [MEDIUM] CWE-125 CVE-2022-42393: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-41145P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-41145 [MEDIUM] CWE-125 CVE-2022-41145: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
nvd
CVE-2022-42401P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42401 [MEDIUM] CWE-125 CVE-2022-42401: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trig
nvd
CVE-2022-42404P4MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42404 [MEDIUM] CWE-125 CVE-2022-42404: This vulnerability allows remote attackers to disclose sensitive information on affected installatio
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can tri
nvd