Skip to main content

Vendor/product archive

apache / pdfbox CVEs

Beta · best-effort

10 CVEs tagged to apache / pdfbox1 Critical, 1 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-33929

Published Apr 14, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Ap…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-23907

Published Mar 10, 2026

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path tra…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2021-31812

Published Jun 12, 2021

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

CVSS 5.5 · Medium

CVE-2018-8036

Published Jul 3, 2018

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFB…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2175

Published Jun 1, 2016

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attack…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1