CVE-2016-6265: Artifex Mupdf

Medium severity, CVSS 5.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

Affected products

Published 2016-09-22. Last modified 2026-06-17.