Unrated severityNVD Advisory· Published Mar 3, 2014· Updated Apr 29, 2026
CVE-2014-2013
CVE-2014-2013
Description
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- bugs.ghostscript.com/show_bug.cginvdExploit
- www.exploit-db.com/exploits/31090nvdExploit
- www.hdwsec.fr/blog/mupdf.htmlnvdExploit
- lists.opensuse.org/opensuse-updates/2014-02/msg00088.htmlnvd
- seclists.org/fulldisclosure/2014/Jan/130nvd
- seclists.org/oss-sec/2014/q1/375nvd
- secunia.com/advisories/58904nvd
- www.debian.org/security/2014/dsa-2951nvd
- www.osvdb.org/102340nvd
- www.securityfocus.com/bid/65036nvd
News mentions
0No linked articles in our index yet.