Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shadowrider09

#53235of 53,624
2.5Total CVSS
Vulnerabilities · 1
PT-2026-40963
2.5
2026-05-14
Podofo · Podofo · CVE-2026-44348
**Name of the Vulnerable Software and Affected Versions** PoDoFo versions 1.0.0 through 1.0.3 **Description** A double-free issue exists in the `compute hash to sign()` function within the src/podofo/private/OpenSSLInternal Ripped.cpp file. If the `EVP DigestFinal` function fails after the `buf` variable has been freed, the Error label triggers a second free of `buf`, leading to heap corruption (a condition where the memory allocator's internal structures are damaged). **Recommendations** Update to version 1.0.4.