CVE-2019-13288: Glyphandcog Xpdfreader
Medium severity, CVSS 5.5. EPSS: 4.6% chance of exploitation in the next 30 days.
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
Affected products
- Glyphandcog Xpdfreader: version 4.01.01 only
Published 2019-07-04. Last modified 2026-06-17.