CVE-2019-9687: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.

Affected products

Published 2019-03-11. Last modified 2026-06-17.