Back

CVE-2019-5067

CRITICAL

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.

Published: Sep 18, 2019 Modified: Jun 17, 2026
CWE-416 CWE-908

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
aspose aspose.pdf_for_c\+\+ 19.2

GitHub Security Advisory GHSA-4pg2-m5v4-8fpj

An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.42%

Top 12% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub