Out-Of-Bounds Read Vulnerability in Soda PDF Desktop by LULU Software
CVE-2025-14410

3.3LOW

Key Information:

Vendor

Soda PDF

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14410?

An out-of-bounds read vulnerability in Soda PDF Desktop could allow remote attackers to disclose sensitive user information. This security issue arises during the parsing of PDF files due to insufficient validation of user-supplied data, leading to a read operation that surpasses allocated object boundaries. Exploitation requires user interaction, as victims must either visit a malicious webpage or open a compromised file. Attackers may exploit this vulnerability in combination with other security flaws to execute arbitrary code within the application context.

Affected Version(s)

Desktop 14.0.506.23016

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.