CVE-2025-2574: Xpdf

Low severity, CVSS 2.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

Affected products

Published 2025-03-20. Last modified 2026-06-17.