Vulnerability Details CVE-2018-7264
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.135
EPSS Ranking 93.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-7264
-
cpe:2.3:a:activepdf:activepdf_toolkit:5.4.2.14043
-
cpe:2.3:a:activepdf:activepdf_toolkit:5.4.3.14134
-
cpe:2.3:a:activepdf:activepdf_toolkit:5.5.0.15028
-
cpe:2.3:a:activepdf:activepdf_toolkit:5.5.1.15339
-
cpe:2.3:a:activepdf:activepdf_toolkit:5.5.2.16278