CVE-2025-46205
01.10.2025, 19:15
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.Enginsight
| Vendor | Product | Version |
|---|---|---|
| podofo_project | podofo | 0.10.0 ≤ 𝑥 ≤ 0.10.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration