CVE-2025-14407
CVE-2025-14407 is a medium-severity vulnerability in Sodapdf Soda Pdf with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- EPSS exploit prediction: 0% (7th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-204993
- Weakness: CWE-119
- Affected product: Sodapdf Soda Pdf
- Published:
- Last modified:
Description
Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-27141.
Frequently asked questions
- What is CVE-2025-14407?
- Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-27141.
- How severe is CVE-2025-14407?
- CVE-2025-14407 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2025-14407 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (7th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-14407?
- CVE-2025-14407 affects Sodapdf Soda Pdf. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-14407?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-14407 have an EU (EUVD) identifier?
- Yes. CVE-2025-14407 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-204993.
- When was CVE-2025-14407 published?
- CVE-2025-14407 was published on 2025-12-23 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:sodapdf:soda_pdf:14.0.509.23030:*:*:*:*:*:*:*
More vulnerabilities in Sodapdf Soda Pdf
- CVE-2025-14415 — High (CVSS 7.8): Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote…
- CVE-2025-14412 — High (CVSS 7.8): Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote…
- CVE-2025-14409 — High (CVSS 7.8): Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows…
- CVE-2025-14406 — High (CVSS 7.8): Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows…
- CVE-2025-14411 — Medium (CVSS 5.5): Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows…
- CVE-2025-14410 — Medium (CVSS 5.5): Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows…
All CVEs affecting Sodapdf Soda Pdf →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-77946 — Critical (CVSS 10.0): A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function…
- CVE-2026-76008 — Critical (CVSS 10.0): A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file…
- CVE-2026-75784 — Critical (CVSS 10.0): A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of…
- CVE-2026-74843 — Critical (CVSS 10.0): A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function…
- CVE-2026-16367 — Critical (CVSS 10.0): Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox…
- CVE-2026-2778 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in…