CVE-2011-4220

SlimPDF Reader - DoS/Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2011-4220.

AI-analyzed exploit summary This exploit generates a malformed PDF file with a large buffer overflow payload followed by a 'startxref' string, targeting a vulnerability in SlimPDF Reader 1.0. The PoC demonstrates a DoS condition by crashing the application when the file is opened.

Description

Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

Exploits (3)

exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/19391

This exploit generates a malformed PDF file with a large buffer overflow payload followed by a 'startxref' string, targeting a vulnerability in SlimPDF Reader 1.0. The PoC demonstrates a DoS condition by crashing the application when the file is opened.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: SlimPDF Reader 1.0
No auth needed
Prerequisites: SlimPDF Reader 1.0 installed on the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/19392

This exploit generates a malformed PDF file with a large buffer overflow payload followed by a 'startxref' string, targeting a memory corruption vulnerability in Able2Extract and Able2Extract Server v6.0. The PoC is designed to crash the application, demonstrating the vulnerability.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Able2Extract and Able2Extract Server v6.0
No auth needed
Prerequisites: Ability to deliver the malicious PDF file to the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
pythondoswindows
https://www.exploit-db.com/exploits/19393

This exploit generates a malformed PDF file with a large buffer overflow payload followed by a 'startxref' string, targeting a memory corruption vulnerability in Able2Doc and Able2Doc Professional v6.0. The PoC is designed to crash the application, demonstrating the vulnerability.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Able2Doc and Able2Doc Professional v6.0
No auth needed
Prerequisites: None
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/275036

Scores

EPSS 0.0738
EPSS Percentile 93.6%

Details

CWE
CWE-264
Status published
Products (1)
investintech/slimpdf_reader
Published Nov 01, 2011
Tracked Since Feb 18, 2026