
Cloud Vulnerability DB
A community-led vulnerabilities database
A global buffer overflow vulnerability was discovered in XPDF (CVE-2022-38236), specifically in the Lexer::getObj(Object*) function located in /xpdf/Lexer.cc. The vulnerability was identified in August 2022 and affects the XPDF PDF viewer software version containing commit ffaf11c (GitHub Issue).
The vulnerability is a global-buffer-overflow that occurs in the Lexer::getObj(Object*) function at line 132 of /xpdf/Lexer.cc. The overflow happens when reading one byte at an address located 4 bytes to the left of the global variable 'specialChars' and 55 bytes to the right of another global variable. The issue has been assigned a CVSS v3 base score of 7.8 (High), with attack vector being Local, requiring user interaction, but no privileges (AttackerKB).
When successfully exploited, this buffer overflow vulnerability could lead to potential code execution or program crash. The vulnerability affects the confidentiality, integrity, and availability of the system, all rated as High according to the CVSS metrics (AttackerKB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."