Loading
Generated remediation guidance and an executive summary. No account required.
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.
Use CWE-674, Qpdf Project vendor hub and Qpdf product page to widen CVE-2018-9918 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-12595, CVE-2022-34503 and CVE-2024-24246 for nearby disclosures in the same product family.