VYPR

Poppler

by Xorg

Source repositories

CVEs (90)

  • CVE-2019-9631CriMar 8, 2019
    risk 0.64cvss 9.8epss 0.04

    Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

  • CVE-2021-30860HigKEVAug 24, 2021
    risk 0.62cvss 7.8epss 0.76

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a…

  • CVE-2017-2820HigJul 12, 2017
    risk 0.58cvss 8.8epss 0.04

    An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary…

  • CVE-2018-21009HigSep 5, 2019
    risk 0.57cvss 8.8epss 0.02

    Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

  • CVE-2019-12293HigMay 23, 2019
    risk 0.57cvss 8.8epss 0.02

    In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

  • CVE-2019-10872HigApr 5, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.

  • CVE-2019-9545HigMar 1, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation…

  • CVE-2019-9543HigMar 1, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service…

  • CVE-2019-9200HigFeb 26, 2019
    risk 0.57cvss 8.8epss 0.03

    A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly…

  • CVE-2017-1000456HigJan 2, 2018
    risk 0.57cvss 8.8epss 0.02

    freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

  • CVE-2017-15565HigOct 17, 2017
    risk 0.57cvss 8.8epss 0.02

    In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.

  • CVE-2022-38784HigAug 30, 2022
    risk 0.51cvss 7.8epss 0.01

    Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the…

  • CVE-2022-38171HigAug 22, 2022
    risk 0.51cvss 7.8epss 0.00

    Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the…

  • CVE-2020-35702HigDec 25, 2020
    risk 0.51cvss 7.8epss 0.01

    DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT…

  • CVE-2012-2142HigJan 9, 2020
    risk 0.51cvss 7.8epss 0.03

    The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

  • CVE-2010-4654HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.01

    poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

  • CVE-2019-7310HigFeb 3, 2019
    risk 0.51cvss 7.8epss 0.02

    In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as…

  • CVE-2017-14617HigSep 20, 2017
    risk 0.51cvss 7.8epss 0.01

    In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

  • CVE-2017-14520HigSep 17, 2017
    risk 0.51cvss 7.8epss 0.01

    In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.

  • CVE-2017-14518HigSep 17, 2017
    risk 0.51cvss 7.8epss 0.01

    In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.

Page 1 of 5