CVE-2018-8036

MEDIUM

Apache PDFBox <2.0.11 - Memory Corruption

Title source: llm
STIX 2.1

Description

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

Scores

CVSS v3 6.5
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (3)
apache/pdfbox 2.0.0 rc1 (3 CPE variants)
apache/pdfbox 1.8.0 - 1.8.14
org.apache.pdfbox/pdfbox 1.8.0 - 1.8.15Maven
Published Jul 03, 2018
Tracked Since Feb 18, 2026