Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet. | |
| Title | Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds | |
| First Time appeared |
Artifex
Artifex mupdf |
|
| Weaknesses | CWE-119 CWE-125 |
|
| CPEs | cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Artifex
Artifex mupdf |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-05T20:23:51.185Z
Reserved: 2026-04-27T17:00:07.970Z
Link: CVE-2026-7233
Updated: 2026-04-29T15:14:50.739Z
Status : Modified
Published: 2026-04-28T07:16:04.067
Modified: 2026-05-05T21:16:23.940
Link: CVE-2026-7233
OpenCVE Enrichment
Updated: 2026-04-28T12:30:31Z