cbcvebase.

Pdf-Xchange Editor vulnerabilities

289 known vulnerabilities affecting pdf-xchange/pdf-xchange_editor.

Total CVEs
289
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH166MEDIUM106LOW17

Vulnerabilities

Page 3 of 15
CVE-2024-8842P3HIGHCVSS 7.8≥ 10.3.0.386, < 10.4.0.388v10.3.0.3862024-11-22
CVE-2024-8842 [HIGH] CWE-457 CVE-2024-8842: PDF-XChange Editor RTF File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This PDF-XChange Editor RTF File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The spec
nvd
CVE-2024-8818P3HIGHCVSS 7.8v10.3.0.3862024-11-22
CVE-2024-8818 [HIGH] CWE-416 CVE-2024-8818: PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnera PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2025-6660P3HIGHCVSS 7.8v10.5.2.3952025-06-25
CVE-2025-6660 [HIGH] CWE-122 CVE-2025-6660: PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The s
nvd
CVE-2025-6644P3HIGHCVSS 7.8v10.5.2.3952025-06-25
CVE-2025-6644 [HIGH] CWE-416 CVE-2025-6644: PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnera PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2025-6640P3HIGHCVSS 7.8v10.5.2.3952025-06-25
CVE-2025-6640 [HIGH] CWE-416 CVE-2025-6640: PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnera PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2025-6645P3HIGHCVSS 7.8v10.5.2.3952025-06-25
CVE-2025-6645 [HIGH] CWE-416 CVE-2025-6645: PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnera PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2022-37350P3HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37350 [HIGH] CWE-125 CVE-2022-37350: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Collab objects. By performing actions in JavaScript, an
nvd
CVE-2022-37349P3HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37349 [HIGH] CWE-125 CVE-2022-37349: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the submitForm method. By performing actions in JavaScript, an attacker
nvd
CVE-2022-37366P3HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37366 [HIGH] CWE-125 CVE-2022-37366: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an at
nvd
CVE-2022-37365P3HIGHCVSS 7.8v9.3.361.02023-03-29
CVE-2022-37365 [HIGH] CWE-749 CVE-2022-37365: This vulnerability allows remote attackers to execute arbitrary code on affected installations of PD This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs method. The application exposes a JavaScript interface that
nvd
CVE-2023-32158P3HIGHCVSS 7.8v9.3.361.02024-05-03
CVE-2023-32158 [HIGH] CWE-787 CVE-2023-32158: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2023-32160P3HIGHCVSS 7.8v9.3.361.02024-05-03
CVE-2023-32160 [HIGH] CWE-787 CVE-2023-32160: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2023-32161P3HIGHCVSS 7.8v9.3.361.02024-05-03
CVE-2023-32161 [HIGH] CWE-787 CVE-2023-32161: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2023-32159P3HIGHCVSS 7.8v9.3.361.02024-05-03
CVE-2023-32159 [HIGH] CWE-787 CVE-2023-32159: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2023-27337P3HIGHCVSS 7.8v9.4.362.02024-05-03
CVE-2023-27337 [HIGH] CWE-125 CVE-2023-27337: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vul PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specif
nvd
CVE-2023-27344P3HIGHCVSS 7.8v9.4.364.02024-05-03
CVE-2023-27344 [HIGH] CWE-787 CVE-2023-27344: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2023-27345P3HIGHCVSS 7.8v9.4.364.02024-05-03
CVE-2023-27345 [HIGH] CWE-787 CVE-2023-27345: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2023-39485P3HIGHCVSS 7.8v9.4.364.0v10.0.1.3712024-05-03
CVE-2023-39485 [HIGH] CWE-787 CVE-2023-39485: PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd
CVE-2024-7352P3HIGHCVSS 7.8≤ 10.3.0.385v10.2.1.3852024-11-22
CVE-2024-7352 [HIGH] CWE-787 CVE-2024-7352: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specifi
nvd
CVE-2023-39490P3HIGHCVSS 7.8v9.5.366.02024-05-03
CVE-2023-39490 [HIGH] CWE-787 CVE-2023-39490: PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The speci
nvd