Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2016-2175

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
apache / pdfbox 1.8.9 1.8.9.x
apache / pdfbox 1.8.7 1.8.7.x
apache / pdfbox 1.8.1 1.8.1.x
apache / pdfbox 1.8.2 1.8.2.x
apache / pdfbox 2.0 2.0.x
apache / pdfbox 1.8.4 1.8.4.x
apache / pdfbox 1.8.3 1.8.3.x
apache / pdfbox 1.8.0 1.8.0.x
apache / pdfbox 2.0-rc3 2.0-rc3.x
apache / pdfbox 2.0-rc2 2.0-rc2.x
apache / pdfbox 1.8.6 1.8.6.x
apache / pdfbox 1.8.11 1.8.11.x
apache / pdfbox 1.8.10 1.8.10.x
apache / pdfbox 2.0-rc1 2.0-rc1.x
apache / pdfbox 1.8.8 1.8.8.x
apache / pdfbox 1.8.5 1.8.5.x
debian / debian_linux 8.0 8.0.x
org.apache.pdfbox / pdfbox - 1.8.12
org.apache.pdfbox / pdfbox 2.0.0 2.0.0.x
org.apache.pdfbox / pdfbox 2.0.0 2.0.1