CVE-2019-13288: Glyphandcog Xpdfreader

Medium severity, CVSS 5.5. EPSS: 4.6% chance of exploitation in the next 30 days.

In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

Affected products

Published 2019-07-04. Last modified 2026-06-17.