Description
A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-06-29
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read in the SlimPDFReader executable, triggered by the TeighaDo function when it processes a malicious PDF file. This flaw allows an attacker to read memory beyond the intended buffer and potentially expose sensitive data, representing a remote information disclosure type weakness (CWE-119, CWE-125).

Affected Systems

Investintech SlimPDFReader versions up to 2.0.14 are affected and are no longer supported by the maintainer; the vulnerability targets the PDF File Handler component within SlimPDFReader.exe.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. The attack vector is remote, as an adversary can send a crafted PDF to the user. Although exploitation results in a read rather than code execution, the potential to leak confidential data means the risk should not be ignored, especially in environments where sensitive PDFs are processed.

Generated by OpenCVE AI on June 29, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall Investintech SlimPDFReader to remove the vulnerable component
  • Restrict remote access to the PDF handling process, using a firewall or access control to allow only trusted users
  • Switch to an alternative, supported PDF viewer that receives timely security updates

Generated by OpenCVE AI on June 29, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Title Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-bounds
First Time appeared Investintech
Investintech slimpdfreader
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:investintech:slimpdfreader:*:*:*:*:*:*:*:*
Vendors & Products Investintech
Investintech slimpdfreader
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Investintech Slimpdfreader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-29T13:41:58.500Z

Reserved: 2026-06-28T07:44:22.927Z

Link: CVE-2026-13522

cve-icon Vulnrichment

Updated: 2026-06-29T13:41:54.383Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T06:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read