VYPR
High severity7.5NVD Advisory· Published Dec 26, 2020· Updated Jun 17, 2026

CVE-2020-35376

CVE-2020-35376

Description

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Xpdf/Xpdfllm-fuzzy2 versions
    <4.03+ 1 more
    • (no CPE)range: <4.03
    • cpe:2.3:a:xpdfreader:xpdf:4.02:*:*:*:*:*:*:*
  • Xpdf/Xpdfdescription
  • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.