rpm package
opensuse/poppler&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/poppler&distro=openSUSE%20Tumbleweed
Vulnerabilities (38)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-102621 | Low | 3.3 | < 26.09.0-3.1 | 26.09.0-3.1 | Sep 29, 2026 | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly a | |
| CVE-2026-102620 | Low | 3.3 | < 26.09.0-3.1 | 26.09.0-3.1 | Sep 29, 2026 | A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disc | |
| CVE-2026-93314 | Med | 6.3 | < 26.09.0-2.1 | 26.09.0-2.1 | Sep 18, 2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has | |
| CVE-2026-93313 | Med | 6.3 | < 26.09.0-2.1 | 26.09.0-2.1 | Sep 18, 2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made | |
| CVE-2025-11896 | Low | — | < 25.09.1-4.1 | 25.09.1-4.1 | Oct 16, 2025 | In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow. | |
| CVE-2025-52885 | Med | — | < 25.09.1-2.1 | 25.09.1-2.1 | Oct 10, 2025 | Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue arises from the use of raw pointers to elements of a | |
| CVE-2025-50420 | Med | 6.5 | < 25.08.0-1.1 | 25.08.0-1.1 | Aug 4, 2025 | An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS). | |
| CVE-2025-52886 | Med | 5.9 | < 25.06.0-1.1 | 25.06.0-1.1 | Jul 2, 2025 | Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue. | |
| CVE-2025-32365 | Med | 4.0 | < 25.04.0-1.1 | 25.04.0-1.1 | Apr 5, 2025 | Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check. | |
| CVE-2025-32364 | Med | 4.0 | < 25.04.0-1.1 | 25.04.0-1.1 | Apr 5, 2025 | A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. | |
| CVE-2024-56378 | Med | 4.3 | < 24.12.0-1.1 | 24.12.0-1.1 | Dec 23, 2024 | libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc. | |
| CVE-2024-6239 | Hig | 7.5 | < 24.07.0-1.1 | 24.07.0-1.1 | Jun 21, 2024 | A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service. | |
| CVE-2022-38784 | Hig | 7.8 | < 22.09.0-1.1 | 22.09.0-1.1 | Aug 30, 2022 | Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vu | |
| CVE-2017-14518 | Hig | 7.8 | < 21.08.0-1.3 | 21.08.0-1.3 | Sep 17, 2017 | In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document. | |
| CVE-2017-14517 | Med | 5.5 | < 21.08.0-1.3 | 21.08.0-1.3 | Sep 17, 2017 | In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document. | |
| CVE-2017-7515 | Med | 5.5 | < 21.08.0-1.3 | 21.08.0-1.3 | Jun 6, 2017 | poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service. | |
| CVE-2013-4474 | — | < 0.49.0-1.1 | 0.49.0-1.1 | Nov 23, 2013 | Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename. | ||
| CVE-2013-4473 | — | < 0.49.0-1.1 | 0.49.0-1.1 | Nov 23, 2013 | Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename. | ||
| CVE-2013-1790 | — | < 0.49.0-1.1 | 0.49.0-1.1 | Apr 9, 2013 | poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function. | ||
| CVE-2013-1789 | — | < 0.49.0-1.1 | 0.49.0-1.1 | Apr 9, 2013 | splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions. |
- affected < 26.09.0-3.1fixed 26.09.0-3.1
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly a
- affected < 26.09.0-3.1fixed 26.09.0-3.1
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disc
- affected < 26.09.0-2.1fixed 26.09.0-2.1
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has
- affected < 26.09.0-2.1fixed 26.09.0-2.1
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made
- affected < 25.09.1-4.1fixed 25.09.1-4.1
In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.
- affected < 25.09.1-2.1fixed 25.09.1-2.1
Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue arises from the use of raw pointers to elements of a
- affected < 25.08.0-1.1fixed 25.08.0-1.1
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).
- affected < 25.06.0-1.1fixed 25.06.0-1.1
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.
- affected < 25.04.0-1.1fixed 25.04.0-1.1
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
- affected < 25.04.0-1.1fixed 25.04.0-1.1
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.
- affected < 24.12.0-1.1fixed 24.12.0-1.1
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
- affected < 24.07.0-1.1fixed 24.07.0-1.1
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.
- affected < 22.09.0-1.1fixed 22.09.0-1.1
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vu
- affected < 21.08.0-1.3fixed 21.08.0-1.3
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
- affected < 21.08.0-1.3fixed 21.08.0-1.3
In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
- affected < 21.08.0-1.3fixed 21.08.0-1.3
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
- CVE-2013-4474Nov 23, 2013affected < 0.49.0-1.1fixed 0.49.0-1.1
Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.
- CVE-2013-4473Nov 23, 2013affected < 0.49.0-1.1fixed 0.49.0-1.1
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.
- CVE-2013-1790Apr 9, 2013affected < 0.49.0-1.1fixed 0.49.0-1.1
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
- CVE-2013-1789Apr 9, 2013affected < 0.49.0-1.1fixed 0.49.0-1.1
splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.
Page 1 of 2