Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32052 |
Mon, 27 Oct 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PDF file. | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue. |
| References |
|
Sat, 18 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:podofo_project:podofo:*:*:*:*:*:*:*:* |
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Podofo Project
Podofo Project podofo |
|
| Vendors & Products |
Podofo Project
Podofo Project podofo |
Wed, 01 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 | |
| Metrics |
cvssV3_1
|
Wed, 01 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PDF file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-27T04:48:40.545Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-46205
Updated: 2025-10-01T18:55:56.308Z
Status : Modified
Published: 2025-10-01T19:15:35.883
Modified: 2025-10-27T05:15:38.780
Link: CVE-2025-46205
No data.
OpenCVE Enrichment
Updated: 2025-10-02T08:45:51Z
EUVD