VYPR
Unrated severityNVD Advisory· Published Dec 8, 2005· Updated Apr 16, 2026

CVE-2005-3192

CVE-2005-3192

Description

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

Affected products

1
  • cpe:2.3:a:xpdf:xpdf:3.0.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

112

News mentions

0

No linked articles in our index yet.