6.8
CVSSv2

CVE-2017-14687

Published: 22/09/2017 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Artifex MuPDF 1.11 allows malicious users to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016cb4f" on Windows. This occurs because of mishandling of XML tag name comparisons.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mupdf 1.11

Vendor Advisories

Debian Bug report logs - #877379 CVE-2017-14685 / CVE-2017-14686 / CVE-2017-14687 Package: mupdf; Maintainer for mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Source for mupdf is src:mupdf (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 1 Oct 2017 07:48:02 UTC Severity: gra ...
Debian Bug report logs - #879055 mupdf: CVE-2017-15587 Package: src:mupdf; Maintainer for src:mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 18 Oct 2017 19:03:01 UTC Severity: grave Tags: patch, security, upstream Found in version mupdf/15-1 Fi ...
Multiple vulnerabilities have been found in MuPDF, a PDF file viewer, which may result in denial of service or the execution of arbitrary code CVE-2017-14685, CVE-2017-14686, and CVE-2017-14687 WangLin discovered that a crafted xps file can crash MuPDF and potentially execute arbitrary code in several ways, since the application m ...
Artifex MuPDF 111 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted xps file This occurs because of mishandling of XML tag name comparisons ...