Pdf-Xchange Editor vulnerabilities

289 known vulnerabilities affecting pdf-xchange/pdf-xchange_editor.

Total CVEs
289
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH166MEDIUM106LOW17

Vulnerabilities

Page 15 of 15
CVE-2022-42401MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42401 [MEDIUM] CWE-125 CVE-2022-42401: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trig
cvelistv5nvd
CVE-2022-42412MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42412 [MEDIUM] CWE-125 CVE-2022-42412: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trig
cvelistv5nvd
CVE-2022-42404MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42404 [MEDIUM] CWE-125 CVE-2022-42404: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can tri
cvelistv5nvd
CVE-2022-42375MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42375 [MEDIUM] CWE-125 CVE-2022-42375: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
cvelistv5nvd
CVE-2022-42388MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.363.02023-01-26
CVE-2022-42388 [MEDIUM] CWE-125 CVE-2022-42388: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
cvelistv5nvd
CVE-2022-42369MEDIUMCVSS 5.5fixed in 9.5.366.0v9.4.362.02023-01-26
CVE-2022-42369 [MEDIUM] CWE-125 CVE-2022-42369: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. Crafted data in a U3D file can trig
cvelistv5nvd
CVE-2018-18689MEDIUMCVSS 5.3v7.0.237.1v7.0.3262021-01-07
CVE-2018-18689 [MEDIUM] CWE-347 CVE-2018-18689: The Portable Document Format (PDF) specification does not provide any information regarding the conc The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Fox
nvd
CVE-2019-17497MEDIUMCVSS 6.5fixed in 8.0.330.02019-10-11
CVE-2019-17497 [MEDIUM] CVE-2019-17497: Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted F Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction.
nvd
CVE-2018-16303HIGHCVSS 7.5≤ 7.0.326.12018-09-01
CVE-2018-16303 [HIGH] CVE-2018-16303: PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a related issue to CVE-2003-1564.
nvd