org.apache.pdfbox:pdfbox
Maven8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.pdfbox:pdfboxpage 1 of 1
- CVE-2016-2175HIGHCVSS 7.8EG 7.8✓ Fixed in 2.0.12016-06-01
vulnerable: 2.0.0
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
- CVE-2018-11797MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.0.122018-10-05
vulnerable: 2.0.0 ... 2.0.9 (12 versions)
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
- CVE-2018-8036MEDIUMCVSS 6.5✓ Fixed in 2.0.112018-07-03
vulnerable: 2.0.0 ... 2.0.9 (14 versions)
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
- CVE-2019-0228CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.152019-04-17
vulnerable: 2.0.14
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
- CVE-2021-27807MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.0.232021-03-19
vulnerable: 2.0.0 ... 2.0.9 (23 versions)
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
- CVE-2021-27906MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.0.232021-03-19
vulnerable: 2.0.0 ... 2.0.9 (23 versions)
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
- CVE-2021-31811MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.0.242021-06-12
vulnerable: 2.0.0 ... 2.0.9 (24 versions)
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
- CVE-2021-31812MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.0.242021-06-12
vulnerable: 2.0.0 ... 2.0.9 (24 versions)
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
Check whether org.apache.pdfbox:pdfbox is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.pdfbox:pdfbox CVEs against the assets you own.
Start Free Scan →