CVE-2023-26930: Xpdfreader Xpdf

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”

Affected products

Published 2023-04-26. Last modified 2026-06-17.