CVE-2019-25550

Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers can paste a 1000-byte buffer into the User Password or Master Password field in the Settings dialog to trigger an application crash when importing PDF files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:verypdf:encrypt_pdf:2.3:*:*:*:*:*:*:*

History

16 Apr 2026, 17:53

Type Values Removed Values Added
Summary
  • (es) Encrypt PDF 2.3 contiene una vulnerabilidad de desbordamiento de búfer que permite a atacantes locales bloquear la aplicación al introducir cadenas excesivamente largas en los campos de contraseña. Los atacantes pueden pegar un búfer de 1000 bytes en el campo de Contraseña de usuario o Contraseña maestra en el diálogo de Configuración para provocar un bloqueo de la aplicación al importar archivos PDF.
CPE cpe:2.3:a:verypdf:encrypt_pdf:2.3:*:*:*:*:*:*:*
References () http://www.verypdf.com - () http://www.verypdf.com - Product
References () https://www.exploit-db.com/exploits/46871 - () https://www.exploit-db.com/exploits/46871 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/encrypt-pdf-denial-of-service-via-buffer-overflow - () https://www.vulncheck.com/advisories/encrypt-pdf-denial-of-service-via-buffer-overflow - Third Party Advisory
First Time Verypdf encrypt Pdf
Verypdf

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-04-16 17:53


NVD link : CVE-2019-25550

Mitre link : CVE-2019-25550

CVE.ORG link : CVE-2019-25550


JSON object : View

Products Affected

verypdf

  • encrypt_pdf
CWE
CWE-787

Out-of-bounds Write