Vulnerabilities > Qpdf Project > Qpdf > 10.0.4

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2021-25786 Use After Free vulnerability in Qpdf Project Qpdf 10.0.4
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
local
low complexity
qpdf-project CWE-416
5.3
2021-07-20 CVE-2021-36978 Out-of-bounds Write vulnerability in Qpdf Project Qpdf
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
local
low complexity
qpdf-project CWE-787
5.5