Back

CVE-2019-5066

CRITICAL

An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in a use-after-free condition. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

Published: Sep 18, 2019 Modified: Jun 17, 2026
CWE-416 CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
aspose aspose.pdf_for_c\+\+ 19.2

GitHub Security Advisory GHSA-jqg4-p627-84cf

An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.38%

Top 18% most likely to be exploited

Threat Score 39.9 / 100

Data Sources

NVD EPSS GitHub