Xpdf
by Xpdf
CVEs (177)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-8102 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2018 | The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml. | ||
| CVE-2018-8101 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2018 | The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml. | ||
| CVE-2018-7455 | Med | 0.36 | 5.5 | 0.01 | Feb 24, 2018 | An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | ||
| CVE-2018-7454 | Med | 0.36 | 5.5 | 0.01 | Feb 24, 2018 | A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | ||
| CVE-2018-7453 | Med | 0.36 | 5.5 | 0.01 | Feb 24, 2018 | Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. | ||
| CVE-2018-7452 | Med | 0.36 | 5.5 | 0.01 | Feb 24, 2018 | A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | ||
| CVE-2018-7175 | Med | 0.36 | 5.5 | 0.01 | Feb 15, 2018 | An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. | ||
| CVE-2018-7174 | Med | 0.36 | 5.5 | 0.01 | Feb 15, 2018 | An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. | ||
| CVE-2018-7173 | Med | 0.36 | 5.5 | 0.01 | Feb 15, 2018 | A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. | ||
| CVE-2011-2902 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2018 | zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name. | ||
| CVE-2020-25725 | Med | 0.33 | 5.0 | 0.01 | Nov 21, 2020 | In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where… | ||
| CVE-2023-3436 | Low | 0.21 | 3.3 | 0.00 | Jun 27, 2023 | Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream. | ||
| CVE-2023-3044 | Low | 0.21 | 3.3 | 0.00 | Jun 2, 2023 | An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large… | ||
| CVE-2024-4568 | Low | 0.19 | 2.9 | 0.00 | May 6, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. | ||
| CVE-2024-4141 | Low | 0.19 | 2.9 | 0.00 | Apr 24, 2024 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers. | ||
| CVE-2024-3900 | Low | 0.19 | 2.9 | 0.00 | Apr 17, 2024 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText. | ||
| CVE-2024-3248 | Low | 0.19 | 2.9 | 0.00 | Apr 2, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow. | ||
| CVE-2024-3247 | Low | 0.19 | 2.9 | 0.00 | Apr 2, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow. | ||
| CVE-2024-2971 | Low | 0.19 | 2.9 | 0.00 | Mar 26, 2024 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file. | ||
| CVE-2023-2664 | Low | 0.19 | 2.9 | 0.00 | May 11, 2023 | In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow. |
- risk 0.36cvss 5.5epss 0.01
The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
- risk 0.36cvss 5.5epss 0.01
The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
- risk 0.36cvss 5.5epss 0.01
An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
- risk 0.36cvss 5.5epss 0.01
A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
- risk 0.36cvss 5.5epss 0.01
Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.
- risk 0.36cvss 5.5epss 0.01
A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
- risk 0.36cvss 5.5epss 0.01
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.
- risk 0.35cvss 5.3epss 0.01
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
- risk 0.33cvss 5.0epss 0.01
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where…
- risk 0.21cvss 3.3epss 0.00
Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.
- risk 0.21cvss 3.3epss 0.00
An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large…
- risk 0.19cvss 2.9epss 0.00
In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
- risk 0.19cvss 2.9epss 0.00
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.
- risk 0.19cvss 2.9epss 0.00
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
- risk 0.19cvss 2.9epss 0.00
In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.
- risk 0.19cvss 2.9epss 0.00
In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.
- risk 0.19cvss 2.9epss 0.00
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.
- risk 0.19cvss 2.9epss 0.00
In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.
Page 6 of 9