CVE-2018-1000039

MEDIUM

Artifex MuPDF < 1.12.0 - Use-After-Free in PDF Parser

Title source: llm
STIX 2.1

Description

In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.

Scores

CVSS v3 6.3
EPSS 0.0070
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
artifex/mupdf < 1.12.0
Published May 24, 2018
Tracked Since Feb 18, 2026