CVE-2019-25549 MEDIUM

CVE-2019-25549: VeryPDF PCL Converter 2.7 Denial of Service via PDF Security

Vendor Verypdf
Product VeryPDF PCL Converter
Weakness CWE-787
Published March 21, 2026
Last update March 24, 2026

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption fields, causing the application to crash when processing PCL files.

Key dates

02Disclosure timeline

March 21, 2026 CVE published
March 24, 2026 Record updated