VYPR

libpoppler

by Poppler (software)

CVEs (2)

  • CVE-2008-2950Jul 7, 2008
    risk 0.04cvss —epss 0.15

    The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.

  • CVE-2024-56378MedDec 23, 2024
    risk 0.00cvss 4.3epss 0.01

    libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.