VYPR

Xpdf

by Xpdf

CVEs (177)

  • CVE-2010-0206MedOct 30, 2019
    risk 0.36cvss 5.5epss 0.01

    xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

  • CVE-2019-17064MedOct 1, 2019
    risk 0.36cvss 5.5epss 0.01

    Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.

  • CVE-2019-16927MedSep 27, 2019
    risk 0.36cvss 5.5epss 0.01

    Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.

  • CVE-2019-16088MedSep 6, 2019
    risk 0.36cvss 5.5epss 0.01

    Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.

  • CVE-2019-15860MedSep 3, 2019
    risk 0.36cvss 5.5epss 0.01

    Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

  • CVE-2019-14294MedJul 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.

  • CVE-2019-14293MedJul 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.

  • CVE-2019-14292MedJul 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.

  • CVE-2019-14291MedJul 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.

  • CVE-2019-14290MedJul 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.

  • CVE-2019-14289MedJul 27, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.

  • CVE-2019-13291MedJul 4, 2019
    risk 0.36cvss 5.5epss 0.01

    In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.

  • CVE-2019-13288MedJul 4, 2019
    risk 0.36cvss 5.5epss 0.05

    In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

  • CVE-2019-13287MedJul 4, 2019
    risk 0.36cvss 5.5epss 0.01

    In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information…

  • CVE-2019-13286MedJul 4, 2019
    risk 0.36cvss 5.5epss 0.01

    In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information…

  • CVE-2019-12958MedJun 25, 2019
    risk 0.36cvss 5.5epss 0.01

    In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.

  • CVE-2019-10026MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.

  • CVE-2019-10025MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

  • CVE-2019-10024MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.

  • CVE-2019-10023MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.

Page 4 of 9