CVE-2019-7321: Artifex Mupdf

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.

Affected products

Published 2019-06-13. Last modified 2026-06-17.