CVE-2019-13288

MEDIUM

Glyphandcog Xpdfreader - Denial of Service

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2019-13288. PoCs published by Fineas, ngtuonghung, WildWestCyberSecurity.

AI-analyzed exploit summary The repository contains minimal information about CVE-2019-13288, describing a DoS vulnerability in Xpdf 4.01.01 due to infinite recursion in Parser::getObj(). However, it lacks functional exploit code or detailed technical analysis, only providing a command and a backtrace image reference.

Description

In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

Exploits (4)

nomisec STUB 2 stars
by Fineas · poc
https://github.com/Fineas/CVE-2019-13288-POC

The repository contains minimal information about CVE-2019-13288, describing a DoS vulnerability in Xpdf 4.01.01 due to infinite recursion in Parser::getObj(). However, it lacks functional exploit code or detailed technical analysis, only providing a command and a backtrace image reference.

Classification
Stub 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Xpdf 4.01.01
No auth needed
Prerequisites: A crafted PDF file
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP
by ngtuonghung · poc
https://github.com/ngtuonghung/CVE-2019-13288

This repository provides a link to a detailed writeup and PoC for CVE-2019-13288, which involves infinite recursion and null pointer dereference vulnerabilities in XPDF. The linked writeup likely contains technical analysis and reproduction steps.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: XPDF
No auth needed
Prerequisites: vulnerable version of XPDF
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WRITEUP
by WildWestCyberSecurity · poc
https://github.com/WildWestCyberSecurity/CVE-2019-13288

This repository provides a detailed technical analysis of CVE-2019-13288, an infinite recursion vulnerability in Xpdf's Parser::getObj() function, including steps to replicate the exploit using AFL++ fuzzing.

Classification
Writeup 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Xpdf 4.01.01
No auth needed
Prerequisites: Xpdf 4.01.01 installation · AFL++ for fuzzing
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB
by gleaming0 · poc
https://github.com/gleaming0/CVE-2019-13288

The repository contains only a README file with general information about Xpdf and a single source file (parseargs.c) unrelated to CVE-2019-13288. No exploit code or technical details about the vulnerability are present.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Xpdf
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0456
EPSS Percentile 90.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-674
Status published
Products (1)
glyphandcog/xpdfreader 4.01.01
Published Jul 04, 2019
Tracked Since Feb 18, 2026