CVE-2019-25549
Severity CVSS v4.0:
MEDIUM
Type:
CWE-787
Out-of-bounds Write
Publication date:
21/03/2026
Last modified:
21/03/2026
Description
VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption fields, causing the application to crash when processing PCL files.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
6.20
Severity 3.x
MEDIUM



