CVE-2025-3154

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 862

Summary

CVE-2025-3154 is a newly disclosed vulnerability in Xpdf 4.05 and earlier versions. This issue involves an out-of-bounds array write vulnerability, which can be triggered by an invalid VerticesPerRow value found within a PDF shading dictionary. Successful exploitation of this vulnerability could result in arbitrary code execution, potentially leading to significant security risks and potential data breaches for affected systems. Users are strongly encouraged to update to the latest version of Xpdf to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Booking System Plugin

Affected Vendors

  • WordPress