Out-of-Bounds Array Write in Xpdf Affected by Vulnerability
CVE-2026-4407

2.1LOW

Key Information:

Vendor

XPDF

Status
Vendor
CVE Published:
18 March 2026

What is CVE-2026-4407?

An out-of-bounds array write vulnerability exists in Xpdf versions 4.06 and earlier, stemming from improper validation of the 'N' field in ICCBased color spaces. This flaw could enable attackers to exploit the software, potentially leading to application crashes or arbitrary code execution.

Affected Version(s)

Xpdf all 4.06

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wooseokdotkim
.