Skip to main content

Vendor archive

flowpaper CVEs

Beta · best-effort

23 CVEs tagged to vendor flowpaper2 Critical, 4 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2023-5200

Published Oct 20, 2023

The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up to, and including, 2.0.3 due to insufficient input sanitiza…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-40197

Published Sep 4, 2023

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-23879

Published Nov 10, 2021

pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23878

Published Nov 10, 2021

pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-19475

Published Jul 21, 2021

An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19474

Published Jul 21, 2021

An issue has been found in function Gfx::doShowText in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Use After Free .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19473

Published Jul 21, 2021

An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19472

Published Jul 21, 2021

An issue has been found in function DCTStream::readHuffSym in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 2 .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19471

Published Jul 21, 2021

An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19470

Published Jul 21, 2021

An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19469

Published Jul 21, 2021

An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19468

Published Jul 21, 2021

An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of siz…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19467

Published Jul 21, 2021

An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19466

Published Jul 21, 2021

An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19465

Published Jul 21, 2021

An issue has been found in function ObjectStream::getObject in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 4 .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19464

Published Jul 21, 2021

An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19463

Published Jul 21, 2021

An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18750

Published Feb 5, 2021

Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11686

Published Jul 3, 2019

The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14947

Published Aug 5, 2018

An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14946

Published Aug 5, 2018

An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9678

Published Oct 17, 2017

FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9677

Published Oct 17, 2017

Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the Swfile parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1