VYPR

npm package

pdfjs-dist

pkg:npm/pdfjs-dist

Vulnerabilities (2)

  • CVE-2024-4367HigMay 14, 2024
    affected < 4.2.67fixed 4.2.67

    A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

  • CVE-2018-5158Jun 11, 2018
    affected >= 2.0.0, < 2.0.550fixed 2.0.550

    The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 5