Out-Of-Bounds Read Vulnerability in PDF-XChange Editor
CVE-2025-0900

3.3LOW

Key Information:

Vendor
CVE Published:
11 March 2025

Summary

A vulnerability in PDF-XChange Editor permits remote attackers to disclose sensitive information due to improper validation of user-supplied data during PDF file parsing. The flaw can lead to a read past the end of an allocated object. To exploit this vulnerability, users must open a malicious PDF file or visit a malicious webpage, facilitating the potential for attackers to execute arbitrary code within the current process context when combined with other vulnerabilities.

Affected Version(s)

PDF-XChange Editor 10.4.0.388

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0900 : Out-Of-Bounds Read Vulnerability in PDF-XChange Editor | SecurityVulnerability.io