Medium severity5.5NVD Advisory· Published Feb 15, 2017· Updated May 13, 2026
CVE-2016-8674
CVE-2016-8674
Description
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.openwall.com/lists/oss-security/2016/10/16/8nvdMailing ListPatchThird Party Advisory
- blogs.gentoo.org/ago/2016/09/22/mupdf-use-after-free-in-pdf_to_num-pdf-object-c/nvdPatchThird Party AdvisoryVDB Entry
- bugs.ghostscript.com/show_bug.cginvdIssue TrackingPatch
- bugs.ghostscript.com/show_bug.cginvdIssue TrackingPatch
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- www.securityfocus.com/bid/93127nvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2017/dsa-3797nvd
News mentions
0No linked articles in our index yet.