<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>PDF XChange Co. Security updates</title><link>https://www.pdf-xchange.com</link><description>PDF XChange Co. - security updates channel</description><language>en</language><ttl>60</ttl><pubDate>Tue, 21 Apr 2026 00:00:00 -0700</pubDate><lastBuildDate>Tue, 21 Apr 2026 00:00:00 -0700</lastBuildDate><atom:link href="https://www.pdf-xchange.com/security-updates/security-updates.xml" rel="self" type="application/rss+xml"/><item><guid isPermaLink="false">tag:pdf-xchange.com,2026:bulletin:25</guid><title>Security updates available in PDF-XChange Editor/Tools 10.8.5.410</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 21 Apr 2026 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.8.5.410, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.8.4.409</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.8.4.409</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Updated third-party libraries used in the PDF-XChange products.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467">
                                            CVE-2025-15467
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2026:bulletin:24</guid><title>Security updates available in PDF-XChange Editor/Tools 10.8.3.408</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 24 Feb 2026 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.8.3.408, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.8.2.407</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.8.2.407</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Add protection against COM hijacking (unintended loading of a malicious DLL registered per-user by the CLSID of a legitimate COM server).</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
            <tr>
            <td>
                <p>Updated third-party libraries used in the PDF-XChange products.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2025:bulletin:23</guid><title>Security updates available in PDF-XChange Editor/Tools 10.7.5.403</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 28 Oct 2025 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.7.5.403, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.7.3.401</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.7.3.401</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.7.3.401</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Updated third-party libraries used in the PDF-XChange products.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
            <tr>
            <td>
                <p>An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor 10.7.3.401.</p><p>By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-58113">
                                            CVE-2025-58113
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li data-list-item-id="eaa8ff9f2ea8fc9700af79e2513f5f237">Discovered by KPC of Cisco Talos.&nbsp;</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li class="ck-list-marker-font-size ck-list-marker-font-family" style="--ck-content-list-marker-font-family:&quot;Aptos&quot;,sans-serif;--ck-content-list-marker-font-size:12.0pt;" data-list-item-id="e378de4c531a32f2b5536bc1ddf8bc747"><span style="font-family:&quot;Aptos&quot;,sans-serif;font-size:12.0pt;">Lee Kwang-Hui</span></li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2025:bulletin:22</guid><title>Security updates available in PDF-XChange 10.7.3.401</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 23 Sep 2025 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.7.3.401, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.7.2.400</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.7.2.400</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.7.2.400</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Fixed a potential local privilege escalation vulnerability in the PDF-XChange Updater.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2040">
                                            CVE-2026-2040
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li data-list-item-id="ec18454213644391e2b43c432c377eff1">Kolja Grassmann (Neodyme AG) working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2025:bulletin:21</guid><title>Security updates available in PDF-XChange Editor/Tools 10.6.1.397</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 22 Jul 2025 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.6.1.397, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.6.0.396;</span>
                                            <span>10.5.2.395</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.6.0.396;</span>
                                            <span>10.5.2.395</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.6.0.396;</span>
                                            <span>10.5.2.395</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395.</p><p>By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27931">
                                            CVE-2025-27931
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47152">
                                            CVE-2025-47152
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Discovered by KPC of Cisco Talos.&nbsp;</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li><span style="font-family:&quot;Arial&quot;,sans-serif;">Suyue Guo and Tianle Yu from UCSB Seclab</span></li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2025:bulletin:20</guid><title>Security updates available in PDF-XChange Editor/Tools 10.6.0.396</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 06 May 2025 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.6.0.396, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.5.2.395</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.5.2.395</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.5.2.395</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files and U3D streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6640">
                                            CVE-2025-6640
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6641">
                                            CVE-2025-6641
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6642">
                                            CVE-2025-6642
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6643">
                                            CVE-2025-6643
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6644">
                                            CVE-2025-6644
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6645">
                                            CVE-2025-6645
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6646">
                                            CVE-2025-6646
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6647">
                                            CVE-2025-6647
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6648">
                                            CVE-2025-6648
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6649">
                                            CVE-2025-6649
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6650">
                                            CVE-2025-6650
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Anonymous working with Trend Micro Zero Day Initiative</li><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PRC files and PRC streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6652">
                                            CVE-2025-6652
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6653">
                                            CVE-2025-6653
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6654">
                                            CVE-2025-6654
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6655">
                                            CVE-2025-6655
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6656">
                                            CVE-2025-6656
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6657">
                                            CVE-2025-6657
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6658">
                                            CVE-2025-6658
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6659">
                                            CVE-2025-6659
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6662">
                                            CVE-2025-6662
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Anonymous working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain GIF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6660">
                                            CVE-2025-6660
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6661">
                                            CVE-2025-6661
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Suyue Guo from UCSB Seclab working with Trend Micro Zero Day Initiative</li><li>RUCSESEC</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files or JPEG2000 streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6651">
                                            CVE-2025-6651
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li><span style="font-family:&quot;Calibri&quot;,sans-serif;font-size:12.0pt;">Anonymous working with Trend Micro Zero Day Initiative</span></li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2025:bulletin:19</guid><title>Security updates available in PDF-XChange Editor/Tools 10.5.2.395</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Wed, 12 Feb 2025 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.5.2.395, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.5.1.394</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.5.1.394</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.5.1.394</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain RTF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2231">
                                            CVE-2025-2231
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2025:bulletin:18</guid><title>Security updates available in PDF-XChange Editor/Tools 10.5.0.393</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 14 Jan 2025 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.5.0.393, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.4.4.392</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.4.4.392</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.4.4.392</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0909">
                                            CVE-2025-0909
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files and U3D streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0910">
                                            CVE-2025-0910
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0911">
                                            CVE-2025-0911
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><p>Anonymous working with Trend Micro Zero Day Initiative</p></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues with XFA files, including untrusted URL invocation, ignoring encryption element in submit action, and importing XML data without user confirmation.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><p><span style="font-family:&quot;Arial&quot;,sans-serif;font-size:10.5pt;">Jörn Henkel</span></p></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2024:bulletin:17</guid><title>Security updates available in PDF-XChange Editor/Tools 10.4.2.392</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 12 Nov 2024 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.4.4.392, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.4.3.391</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.4.3.391</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.4.3.391</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files and U3D streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0908">
                                            CVE-2025-0908
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Anonymous working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2024:bulletin:16</guid><title>Security updates available in PDF-XChange Editor/Tools 10.4.2.390</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 07 Oct 2024 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.4.2.390, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.4.0.388</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.4.0.388</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.4.0.388</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0900">
                                            CVE-2025-0900
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0902">
                                            CVE-2025-0902
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0904">
                                            CVE-2025-0904
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain RTF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0903">
                                            CVE-2025-0903
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JBIG2 files or JBIG2 streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0905">
                                            CVE-2025-0905
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0907">
                                            CVE-2025-0907
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2024:bulletin:15</guid><title>Security updates available in PDF-XChange Editor/Tools 10.4.1.389</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 23 Sep 2024 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.4.1.389, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.4.0.388</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.4.0.388</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0899">
                                            CVE-2025-0899
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0901">
                                            CVE-2025-0901
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2024:bulletin:14</guid><title>Security updates available in PDF-XChange Editor/Tools 10.4.0.388</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 09 Sep 2024 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.4.0.388, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.3.1.387</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.3.1.387</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.3.1.387</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Updated third-party libraries used in the PDF-XChange products.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8844">
                                            CVE-2024-8844
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8845">
                                            CVE-2024-8845
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8849">
                                            CVE-2024-8849
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Mat Powell of Trend Micro Zero Day Initiative</li><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JBIG2 files or JBIG2 streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8843">
                                            CVE-2024-8843
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain RTF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8842">
                                            CVE-2024-8842
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8846">
                                            CVE-2024-8846
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8847">
                                            CVE-2024-8847
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8848">
                                            CVE-2024-8848
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2024:bulletin:13</guid><title>Security updates available in PDF-XChange Editor/Tools 10.3.1.387</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 18 Jun 2024 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

&lt;p&gt;Released version 10.3.1.387, which addresses potential security and stability issues.&lt;/p&gt;
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.3.0.386</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.3.0.386</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.3.0.386</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files and U3D streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8812">
                                            CVE-2024-8812
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8813">
                                            CVE-2024-8813
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8814">
                                            CVE-2024-8814
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8815">
                                            CVE-2024-8815
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8816">
                                            CVE-2024-8816
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8817">
                                            CVE-2024-8817
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8818">
                                            CVE-2024-8818
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8819">
                                            CVE-2024-8819
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8820">
                                            CVE-2024-8820
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8821">
                                            CVE-2024-8821
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8822">
                                            CVE-2024-8822
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8825">
                                            CVE-2024-8825
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8841">
                                            CVE-2024-8841
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8834">
                                            CVE-2024-8834
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8836">
                                            CVE-2024-8836
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS/OXPS files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8826">
                                            CVE-2024-8826
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8830">
                                            CVE-2024-8830
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8831">
                                            CVE-2024-8831
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8833">
                                            CVE-2024-8833
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8837">
                                            CVE-2024-8837
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8838">
                                            CVE-2024-8838
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li><li>Mat Powell of Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8828">
                                            CVE-2024-8828
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8829">
                                            CVE-2024-8829
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8832">
                                            CVE-2024-8832
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JBIG2 files or JBIG2 streams in PDF files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8823">
                                            CVE-2024-8823
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8824">
                                            CVE-2024-8824
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8835">
                                            CVE-2024-8835
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8839">
                                            CVE-2024-8839
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8840">
                                            CVE-2024-8840
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PNM files.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8827">
                                            CVE-2024-8827
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul><li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li></ul></td>
        </tr>
            <tr>
            <td>
                <p>Updated third-party libraries used in the PDF-XChange products.</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2024:bulletin:12</guid><title>Security updates available in PDF-XChange Editor/Tools 10.3.0.386</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 29 Apr 2024 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 10.3.0.386, which addresses potential security and stability issues. Third-party libraries are updated to the latest stable versions.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.2.1.385</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.2.1.385</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.2.1.385</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7352">
                                            CVE-2024-7352
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Anonymous working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Updated third-party libraries used in the PDF-XChange products.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:11</guid><title>Security updates available in PDF-XChange Editor/Tools 10.1.3.383</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 14 Nov 2023 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 10.1.3.383, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.1.2.382</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.1.2.382</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.1.2.382</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27324">
                                            CVE-2024-27324
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Francis Provencher {PRL} working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:10</guid><title>Security updates available in PDF-XChange Editor/Tools 10.1.2.382</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 23 Oct 2023 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 10.1.2.382, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.1.1.381</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.1.1.381</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.1.1.381</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27325">
                                            CVE-2024-27325
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27328">
                                            CVE-2024-27328
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27330">
                                            CVE-2024-27330
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27331">
                                            CVE-2024-27331
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG files and JPEG streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27332">
                                            CVE-2024-27332
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27326">
                                            CVE-2024-27326
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27329">
                                            CVE-2024-27329
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Updated third-party libraries used in the PDF-XChange products.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4863">
                                            CVE-2023-4863
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27327">
                                            CVE-2024-27327
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td></td>
        </tr>
            <tr>
            <td>
                Added server certificate verification into the PDF-XChange Updater to avoid downloading installers from the wrong servers.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27323">
                                            CVE-2024-27323
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Bobby Gould and Anthony Fuller of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:9</guid><title>Security updates available in PDF-XChange Editor/Tools 10.1.1.381</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 19 Sep 2023 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 10.1.1.381, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.1.0.380</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.1.0.380</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.1.0.380</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42106">
                                            CVE-2023-42106
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42107">
                                            CVE-2023-42107
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42108">
                                            CVE-2023-42108
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42109">
                                            CVE-2023-42109
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42110">
                                            CVE-2023-42110
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42111">
                                            CVE-2023-42111
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42112">
                                            CVE-2023-42112
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPG files or JPG streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42111">
                                            CVE-2023-42111
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:8</guid><title>Security updates available in PDF-XChange Editor/Tools 10.1.0.380</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 05 Sep 2023 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 10.1.0.380, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>10.0.1.371</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>10.0.1.371</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>10.0.1.371</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42077">
                                            CVE-2023-42077
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42080">
                                            CVE-2023-42080
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42081">
                                            CVE-2023-42081
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42084">
                                            CVE-2023-42084
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42085">
                                            CVE-2023-42085
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42086">
                                            CVE-2023-42086
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42087">
                                            CVE-2023-42087
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Anonymous working with Trend Micro Zero Day Initiative</li>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG files and JPEG streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42082">
                                            CVE-2023-42082
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42083">
                                            CVE-2023-42083
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42088">
                                            CVE-2023-42088
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Anonymous working with Trend Micro Zero Day Initiative</li>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42075">
                                            CVE-2023-42075
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Anonymous working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42071">
                                            CVE-2023-42071
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42076">
                                            CVE-2023-42076
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
	<li>rgod working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files and JPEG2000 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37351">
                                            CVE-2022-37351
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39483">
                                            CVE-2023-39483
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39484">
                                            CVE-2023-39484
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39485">
                                            CVE-2023-39485
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39486">
                                            CVE-2023-39486
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42045">
                                            CVE-2023-42045
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42046">
                                            CVE-2023-42046
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42047">
                                            CVE-2023-42047
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42048">
                                            CVE-2023-42048
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42072">
                                            CVE-2023-42072
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42078">
                                            CVE-2023-42078
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42079">
                                            CVE-2023-42079
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:7</guid><title>Security updates available in PDF-XChange Editor/Tools 10.0.0.370</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Wed, 14 Jun 2023 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 10.0.0.370, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.5.368.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.5.368.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.5.368.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40471">
                                            CVE-2023-40471
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40472">
                                            CVE-2023-40472
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42040">
                                            CVE-2023-42040
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42041">
                                            CVE-2023-42041
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42042">
                                            CVE-2023-42042
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42043">
                                            CVE-2023-42043
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42044">
                                            CVE-2023-42044
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42070">
                                            CVE-2023-42070
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42073">
                                            CVE-2023-42073
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42074">
                                            CVE-2023-42074
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>kimiya working with Trend Micro Zero Day Initiative</li>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
	<li>Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42049">
                                            CVE-2023-42049
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42050">
                                            CVE-2023-42050
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PRC files and PRC streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42051">
                                            CVE-2023-42051
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42052">
                                            CVE-2023-42052
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42053">
                                            CVE-2023-42053
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42054">
                                            CVE-2023-42054
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42055">
                                            CVE-2023-42055
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42056">
                                            CVE-2023-42056
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42059">
                                            CVE-2023-42059
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42060">
                                            CVE-2023-42060
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42061">
                                            CVE-2023-42061
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42063">
                                            CVE-2023-42063
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files and U3D streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42057">
                                            CVE-2023-42057
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42058">
                                            CVE-2023-42058
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42062">
                                            CVE-2023-42062
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42064">
                                            CVE-2023-42064
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JBIG2 files or JBIG2 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42067">
                                            CVE-2023-42067
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42068">
                                            CVE-2023-42068
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42069">
                                            CVE-2023-42069
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Anonymous working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files or JPEG2000 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42065">
                                            CVE-2023-42065
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42066">
                                            CVE-2023-42066
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:6</guid><title>Security updates available in PDF-XChange Editor/Tools 9.5.368.0</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Wed, 05 Apr 2023 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 9.5.368.0, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.5.367.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.5.367.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.5.367.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS/OXPS files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40469">
                                            CVE-2023-40469
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39506">
                                            CVE-2023-39506
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>kimiya working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40468">
                                            CVE-2023-40468
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files or JPEG2000 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40470">
                                            CVE-2023-40470
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2023:bulletin:5</guid><title>Security updates available in PDF-XChange Editor/Tools 9.5.367.0</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 06 Mar 2023 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 9.5.367.0, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.5.366.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.5.366.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.5.366.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG files or JPEG streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39497">
                                            CVE-2023-39497
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39498">
                                            CVE-2023-39498
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39499">
                                            CVE-2023-39499
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39500">
                                            CVE-2023-39500
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>hades_kito working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS/OXPS files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39494">
                                            CVE-2023-39494
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39501">
                                            CVE-2023-39501
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39502">
                                            CVE-2023-39502
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39503">
                                            CVE-2023-39503
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39504">
                                            CVE-2023-39504
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Andrea Micalizzi aka rgod working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39491">
                                            CVE-2023-39491
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39496">
                                            CVE-2023-39496
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>hades_kito working with Trend Micro Zero Day Initiative</li>
	<li>Andrea Micalizzi aka rgod working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39493">
                                            CVE-2023-39493
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39495">
                                            CVE-2023-39495
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39505">
                                            CVE-2023-39505
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Andrea Micalizzi aka rgod working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39490">
                                            CVE-2023-39490
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39492">
                                            CVE-2023-39492
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>hades_kito working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2022:bulletin:4</guid><title>Security updates available in PDF-XChange Editor/Tools 9.5.366.0</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 12 Dec 2022 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 9.5.366.0, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.5.365.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.5.365.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.5.365.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39488">
                                            CVE-2023-39488
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39489">
                                            CVE-2023-39489
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2022:bulletin:3</guid><title>Security updates available in PDF-XChange Editor/Tools 9.5.365.0</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 28 Nov 2022 00:00:00 -0800</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Released version 9.5.365.0, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.4.364.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.4.364.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.4.364.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27342">
                                            CVE-2023-27342
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27343">
                                            CVE-2023-27343
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files or JPEG2000 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39485">
                                            CVE-2023-39485
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39486">
                                            CVE-2023-39486
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files or U3D streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42394">
                                            CVE-2022-42394
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27348">
                                            CVE-2023-27348
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27344">
                                            CVE-2023-27344
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27345">
                                            CVE-2023-27345
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39487">
                                            CVE-2023-39487
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PNG files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27339">
                                            CVE-2023-27339
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27340">
                                            CVE-2023-27340
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2022:bulletin:2</guid><title>Security updates available in PDF-XChange Editor/Tools 9.4.364.0</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Tue, 27 Sep 2022 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Release version 9.4.364.0, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.4.362.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.4.362.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.4.362.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain U3D files or U3D streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41143">
                                            CVE-2022-41143
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41144">
                                            CVE-2022-41144
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41145">
                                            CVE-2022-41145
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41146">
                                            CVE-2022-41146
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41147">
                                            CVE-2022-41147
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41148">
                                            CVE-2022-41148
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41149">
                                            CVE-2022-41149
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41150">
                                            CVE-2022-41150
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41151">
                                            CVE-2022-41151
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41152">
                                            CVE-2022-41152
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41153">
                                            CVE-2022-41153
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42369">
                                            CVE-2022-42369
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42370">
                                            CVE-2022-42370
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42371">
                                            CVE-2022-42371
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42372">
                                            CVE-2022-42372
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42373">
                                            CVE-2022-42373
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42374">
                                            CVE-2022-42374
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42375">
                                            CVE-2022-42375
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42376">
                                            CVE-2022-42376
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42377">
                                            CVE-2022-42377
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42378">
                                            CVE-2022-42378
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42379">
                                            CVE-2022-42379
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42380">
                                            CVE-2022-42380
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42381">
                                            CVE-2022-42381
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42382">
                                            CVE-2022-42382
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42383">
                                            CVE-2022-42383
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42384">
                                            CVE-2022-42384
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42385">
                                            CVE-2022-42385
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42386">
                                            CVE-2022-42386
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42387">
                                            CVE-2022-42387
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42388">
                                            CVE-2022-42388
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42389">
                                            CVE-2022-42389
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42390">
                                            CVE-2022-42390
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42391">
                                            CVE-2022-42391
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42392">
                                            CVE-2022-42392
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42393">
                                            CVE-2022-42393
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
	<li>Tran Van Khang (VinCSS)</li>
	<li>Rocco Calvi (@TerR0C)</li>
	<li>Anonymous working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain TIFF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42416">
                                            CVE-2023-42416
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42417">
                                            CVE-2023-42417
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42418">
                                            CVE-2023-42418
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42419">
                                            CVE-2023-42419
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42420">
                                            CVE-2023-42420
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42421">
                                            CVE-2023-42421
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42423">
                                            CVE-2023-42423
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27338">
                                            CVE-2023-27338
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27341">
                                            CVE-2023-27341
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42404">
                                            CVE-2022-42404
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42405">
                                            CVE-2022-42405
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42406">
                                            CVE-2022-42406
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42407">
                                            CVE-2022-42407
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42408">
                                            CVE-2022-42408
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JBIG2 files or JBIG2 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42398">
                                            CVE-2022-42398
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42409">
                                            CVE-2022-42409
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files or JPEG2000 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42411">
                                            CVE-2022-42411
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42412">
                                            CVE-2022-42412
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42413">
                                            CVE-2022-42413
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42414">
                                            CVE-2022-42414
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42415">
                                            CVE-2022-42415
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42399">
                                            CVE-2022-42399
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42400">
                                            CVE-2022-42400
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42401">
                                            CVE-2022-42401
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42402">
                                            CVE-2022-42402
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42403">
                                            CVE-2022-42403
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PGM files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42410">
                                            CVE-2022-42410
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27337">
                                            CVE-2023-27337
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain XPS/OXPS files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42395">
                                            CVE-2022-42395
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42396">
                                            CVE-2022-42396
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42397">
                                            CVE-2022-42397
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Tran Van Khang - khangkito (VinCSS) working with Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item><item><guid isPermaLink="false">tag:pdf-xchange.com,2022:bulletin:1</guid><title>Security updates available in PDF-XChange Editor/Tools 9.4.362.0</title><link>https://www.pdf-xchange.com/support/security-bulletins.html</link><pubDate>Mon, 08 Aug 2022 00:00:00 -0700</pubDate><description><![CDATA[<h2>Summary</h2>

<p>Release version 9.4.362.0, which addresses potential security and stability issues.</p>
    <h3>Affected versions</h3>
    <table>
        <thead>
        <tr>
            <th style="text-align: left">Product</th>
            <th style="text-align: left">Version</th>
        </tr>
        </thead>
        <tbody style="vertical-align: baseline">
                    <tr>
                <td>PDF-XChange Editor</td>
                <td>
                                            <span>9.3.361.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-Tools</td>
                <td>
                                            <span>9.3.361.0</span>
                                    </td>
            </tr>
                    <tr>
                <td>PDF-XChange PRO</td>
                <td>
                                            <span>9.3.361.0</span>
                                    </td>
            </tr>
                </tbody>
    </table>

<h3>Vulnerability details</h3>
<table>
    <thead>
    <tr>
        <th style="text-align: left">Brief</th>
        <th style="text-align: left">Acknowledgement</th>
    </tr>
    </thead>
    <tbody style="vertical-align: baseline">
            <tr>
            <td>
                <p>Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JavaScripts</p>
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37349">
                                            CVE-2022-37349
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37350">
                                            CVE-2022-37350
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37365">
                                            CVE-2022-37365
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37367">
                                            CVE-2022-37367
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37366">
                                            CVE-2022-37366
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37368">
                                            CVE-2022-37368
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain EMF/WMF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37364">
                                            CVE-2022-37364
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37360">
                                            CVE-2022-37360
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37353">
                                            CVE-2022-37353
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37352">
                                            CVE-2022-37352
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37363">
                                            CVE-2022-37363
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JBIG2 files or JBIG2 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37369">
                                            CVE-2022-37369
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37370">
                                            CVE-2022-37370
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37371">
                                            CVE-2022-37371
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37372">
                                            CVE-2022-37372
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37373">
                                            CVE-2022-37373
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PBM/PGM/PPM files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37356">
                                            CVE-2022-37356
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37362">
                                            CVE-2022-37362
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG files or JPEG streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37354">
                                            CVE-2022-37354
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37355">
                                            CVE-2022-37355
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37358">
                                            CVE-2022-37358
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37359">
                                            CVE-2022-37359
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain JPEG2000 files or JPEG2000 streams in PDF files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37361">
                                            CVE-2022-37361
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32158">
                                            CVE-2023-32158
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32159">
                                            CVE-2023-32159
                                        </a>
                                    </div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32160">
                                            CVE-2023-32160
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37375">
                                            CVE-2022-37375
                                        </a>
                                    </div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain ICO files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37357">
                                            CVE-2022-37357
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PNG files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-37374">
                                            CVE-2022-37374
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
            <tr>
            <td>
                Addressed potential issues where the application could be exposed to Use-after-Free, Out-of-Bounds Read, or Type Confusion vulnerability and crash, which could be exploited by attackers to execute remote code or disclose information. This occurs due to the access of null pointer/wild pointer or reference to the object that has been deleted without proper validation when handling certain PNG files.
                                    <div style="margin: 20px 0; display: flex; flex-wrap: wrap; gap: 20px;">
                                                    <div>
                                                                    <div>
                                        <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32161">
                                            CVE-2023-32161
                                        </a>
                                    </div>
                                                            </div>
                                                    <div>
                                                            </div>
                                                    <div>
                                                            </div>
                                            </div>
                            </td>
            <td><ul>
	<li>Mat Powell of Trend Micro Zero Day Initiative</li>
</ul></td>
        </tr>
        </tbody>
</table>]]></description></item></channel></rss>
