CVE-2025-7462
Last modified
CVE-2025-7462 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c of the component New Output File Open Error Handler. The manipulation leads to null pointer dereference. It is possible to initiate the attack remotely. The identifier of the patch is 619a106ba4c4abed95110f84d5efcd7aee38c7cb. It is recommended to apply a patch to fix this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-7462?
How severe is CVE-2025-7462?
How do I fix CVE-2025-7462?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-7456A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-7457A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-7458An integer overflow in the sqlite3KeyInfoFromExprList functi…9.1
- CVE-2025-7459A vulnerability classified as critical was found in code-pro…9.8
- CVE-2025-7460A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B2…8.8
- CVE-2025-7461A vulnerability was found in code-projects Modern Bag 1.0 an…9.8
- CVE-2025-7463A vulnerability was found in Tenda FH1201 1.2.0.14. It has b…8.8
- CVE-2025-7464A vulnerability classified as problematic has been found in …6.3
- CVE-2025-7465A vulnerability classified as critical was found in Tenda FH…8.8
- CVE-2025-7466A vulnerability, which was classified as critical, has been …9.8
- CVE-2025-7467A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-7468A vulnerability has been found in Tenda FH1201 1.2.0.14 and …8.8
Are you affected by CVE-2025-7462?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
