← Back to browse · API

CVE-2019-5067

Severity
CRITICAL
CVSS
9.8
EPSS
0.03415
Risk score
40.4
CISA KEV
No
PoC
No
Published
2019-09-18
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14672, GHSA-4PG2-M5V4-8FPJ
Products
Talos:Aspose Aspose.PDF 19.2 for C++
Sources
euvd EUVD-2019-14672

Description

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

References