pdfforge PDF Architect Out-of-Bounds Read Vulnerability Allowing Information Disclosure

Vulnerability

An out-of-bounds read vulnerability has been identified in pdfforge PDF Architect, specifically within the PDF file parsing component. This issue arises from inadequate validation of user-supplied data, leading to the potential for reading beyond the end of an allocated object. As a result, remote attackers could exploit this vulnerability to disclose sensitive information on affected installations. User interaction is required, as the target must open a malicious PDF file or visit a harmful webpage. Additionally, this vulnerability could be leveraged alongside others to execute arbitrary code within the current process context.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure. Furthermore, it may allow for arbitrary code execution in the context of the current process, especially if combined with other vulnerabilities.

Remediation

Due to the nature of this vulnerability, the primary recommendation is to limit interactions with the product.

Added: Dec 23, 2025, 10:33 PM
Updated: Dec 23, 2025, 10:33 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
2.5
exploitability
4.4
remediation
7.9
relevance
1.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.