CVE-2019-11493
VeryPDF PDF Editor vulnerability analysis and mitigation

Overview

VeryPDF 4.1 contains a memory overflow vulnerability in the pdfocx!CxImageTIF::operator component within pdfocx.ocx, which is used by pdfeditor.exe and pdfcmd.exe. The vulnerability was discovered and disclosed in April 2019 (NVD).

Technical details

The vulnerability is a memory overflow condition that occurs in the pdfocx!CxImageTIF::operator functionality within the pdfocx.ocx component. When processing certain PDF files, the application fails to properly validate input, leading to a memory overflow condition that can result in code execution (VDA Labs).

Impact

The vulnerability allows attackers to execute arbitrary code on the affected system through specially crafted PDF files. This could potentially lead to complete system compromise within the context of the application's privileges (NVD).

Additional resources


SourceThis report was generated using AI

Related VeryPDF PDF Editor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-11493HIGH7.8
  • VeryPDF PDF EditorVeryPDF PDF Editor
  • cpe:2.3:a:verypdf:verypdf
NoNoApr 26, 2019
CVE-2019-25550MEDIUM6.9
  • VeryPDF PDF EditorVeryPDF PDF Editor
  • cpe:2.3:a:verypdf:verypdf
NoNoMar 21, 2026
CVE-2019-25549MEDIUM6.9
  • VeryPDF PDF EditorVeryPDF PDF Editor
  • cpe:2.3:a:verypdf:verypdf
NoNoMar 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management