CVE-2012-6535: Djvulibre Project Djvulibre

High severity, CVSS 9.3. EPSS: 4.6% chance of exploitation in the next 30 days.

DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.

Affected products

  • Djvulibre Project Djvulibre: up to and including 3.5.25; version 3.5.1 only; version 3.5.2 only; version 3.5.3 only; version 3.5.4 only; version 3.5.5 only; …

Published 2013-12-02. Last modified 2026-06-16.