CVE-2017-8787: Podofo Project Podofo

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted PDF file.

Affected products

Published 2017-05-05. Last modified 2026-06-17.