CVE-2019-13288
MEDIUM 5.5EPSS 4.6%
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
- CVSS v3.0
- 5.5 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P - EPSS
- 4.56% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2019-07-04
- Updated
- 2024-08-04
Proof-of-concept exploits (3)
- Fineas/CVE-2019-13288-POC2★ · 2023-12-21
- WildWestCyberSecurity/CVE-2019-132880★ · 2025-05-24
- gleaming0/CVE-2019-132880★ · 2023-09-16