Vendor CVEs
Xpdf
All CVEs
178 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-30860 | Hig | 0.62 | 7.8 | 0.76 | KEV | Aug 24, 2021 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a… | |
| CVE-2024-7868 | Hig | 0.53 | 8.2 | 0.00 | Aug 15, 2024 | In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address. | ||
| CVE-2022-38222 | Hig | 0.51 | 7.8 | 0.00 | Sep 29, 2022 | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact. | ||
| CVE-2022-38928 | Hig | 0.51 | 7.8 | 0.00 | Sep 21, 2022 | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. | ||
| CVE-2022-24107 | Hig | 0.51 | 7.8 | 0.00 | Aug 30, 2022 | Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. | ||
| CVE-2022-24106 | Hig | 0.51 | 7.8 | 0.00 | Aug 30, 2022 | In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc. | ||
| CVE-2022-38171 | Hig | 0.51 | 7.8 | 0.00 | Aug 22, 2022 | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the… | ||
| CVE-2022-38238 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc. | ||
| CVE-2022-38237 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc. | ||
| CVE-2022-38236 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc. | ||
| CVE-2022-38231 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc. | ||
| CVE-2022-38229 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc. | ||
| CVE-2022-38228 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc. | ||
| CVE-2022-38227 | Hig | 0.51 | 7.8 | 0.00 | Aug 16, 2022 | XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp. | ||
| CVE-2022-33108 | Hig | 0.51 | 7.8 | 0.01 | Jun 28, 2022 | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. | ||
| CVE-2022-30524 | Hig | 0.51 | 7.8 | 0.02 | May 9, 2022 | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote… | ||
| CVE-2020-24999 | Hig | 0.51 | 7.8 | 0.01 | Sep 3, 2020 | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified… | ||
| CVE-2020-24996 | Hig | 0.51 | 7.8 | 0.01 | Sep 3, 2020 | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation… | ||
| CVE-2012-2142 | Hig | 0.51 | 7.8 | 0.03 | Jan 9, 2020 | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | ||
| CVE-2019-16115 | Hig | 0.51 | 7.8 | 0.01 | Sep 8, 2019 | In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted… | ||
| CVE-2019-14288 | Hig | 0.51 | 7.8 | 0.01 | Jul 27, 2019 | An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case. | ||
| CVE-2019-13289 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. | ||
| CVE-2019-13283 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF… | ||
| CVE-2019-13282 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted… | ||
| CVE-2019-13281 | Hig | 0.51 | 7.8 | 0.01 | Jul 4, 2019 | In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file… | ||
| CVE-2019-12957 | Hig | 0.51 | 7.8 | 0.01 | Jun 25, 2019 | In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an… | ||
| CVE-2019-9878 | Hig | 0.51 | 7.8 | 0.01 | Mar 21, 2019 | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of… | ||
| CVE-2019-9877 | Hig | 0.51 | 7.8 | 0.01 | Mar 21, 2019 | There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation… | ||
| CVE-2019-9589 | Hig | 0.51 | 7.8 | 0.01 | Mar 6, 2019 | There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault)… | ||
| CVE-2019-9588 | Hig | 0.51 | 7.8 | 0.01 | Mar 6, 2019 | There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified… | ||
| CVE-2019-9587 | Hig | 0.51 | 7.8 | 0.01 | Mar 6, 2019 | There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other… | ||
| CVE-2018-11033 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2018 | The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data. | ||
| CVE-2018-8100 | Hig | 0.51 | 7.8 | 0.01 | Mar 14, 2018 | The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml. | ||
| CVE-2021-36493 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. | ||
| CVE-2021-40226 | Hig | 0.49 | 7.5 | 0.01 | Nov 10, 2022 | xpdfreader 4.03 is vulnerable to Buffer Overflow. | ||
| CVE-2020-35376 | Hig | 0.49 | 7.5 | 0.02 | Dec 26, 2020 | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function. | ||
| CVE-2019-12515 | Hig | 0.46 | 7.1 | 0.01 | Jun 2, 2019 | There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a… | ||
| CVE-2019-12493 | Hig | 0.46 | 7.1 | 0.01 | May 31, 2019 | A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops… | ||
| CVE-2019-12360 | Hig | 0.46 | 7.1 | 0.01 | May 27, 2019 | A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak… | ||
| CVE-2024-7867 | Med | 0.40 | 6.2 | 0.00 | Aug 15, 2024 | In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero. | ||
| CVE-2024-7866 | Med | 0.36 | 5.5 | 0.00 | Aug 15, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow. | ||
| CVE-2024-4976 | Med | 0.36 | 5.5 | 0.00 | May 15, 2024 | Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference. | ||
| CVE-2022-48545 | Med | 0.36 | 5.5 | 0.00 | Aug 22, 2023 | An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02. | ||
| CVE-2023-26930 | Med | 0.36 | 5.5 | 0.00 | Apr 26, 2023 | Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.” | ||
| CVE-2022-45587 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2023 | Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service. | ||
| CVE-2022-45586 | Med | 0.36 | 5.5 | 0.00 | Feb 15, 2023 | Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service. | ||
| CVE-2022-43071 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2022 | A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | ||
| CVE-2022-43295 | Med | 0.36 | 5.5 | 0.00 | Nov 14, 2022 | XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795. | ||
| CVE-2022-41844 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088. | ||
| CVE-2022-41843 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928. |
- risk 0.62cvss 7.8epss 0.76
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a…
- risk 0.53cvss 8.2epss 0.00
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
- risk 0.51cvss 7.8epss 0.00
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
- risk 0.51cvss 7.8epss 0.00
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
- risk 0.51cvss 7.8epss 0.00
Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
- risk 0.51cvss 7.8epss 0.00
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
- risk 0.51cvss 7.8epss 0.00
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the…
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.
- risk 0.51cvss 7.8epss 0.00
XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp.
- risk 0.51cvss 7.8epss 0.01
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
- risk 0.51cvss 7.8epss 0.02
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote…
- risk 0.51cvss 7.8epss 0.01
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified…
- risk 0.51cvss 7.8epss 0.01
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation…
- risk 0.51cvss 7.8epss 0.03
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
- risk 0.51cvss 7.8epss 0.01
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted…
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
- risk 0.51cvss 7.8epss 0.01
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.
- risk 0.51cvss 7.8epss 0.01
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF…
- risk 0.51cvss 7.8epss 0.01
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted…
- risk 0.51cvss 7.8epss 0.01
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file…
- risk 0.51cvss 7.8epss 0.01
In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an…
- risk 0.51cvss 7.8epss 0.01
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of…
- risk 0.51cvss 7.8epss 0.01
There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation…
- risk 0.51cvss 7.8epss 0.01
There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault)…
- risk 0.51cvss 7.8epss 0.01
There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified…
- risk 0.51cvss 7.8epss 0.01
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other…
- risk 0.51cvss 7.8epss 0.01
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.
- risk 0.51cvss 7.8epss 0.01
The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
- risk 0.49cvss 7.5epss 0.01
xpdfreader 4.03 is vulnerable to Buffer Overflow.
- risk 0.49cvss 7.5epss 0.02
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
- risk 0.46cvss 7.1epss 0.01
There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a…
- risk 0.46cvss 7.1epss 0.01
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops…
- risk 0.46cvss 7.1epss 0.01
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak…
- risk 0.40cvss 6.2epss 0.00
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
- risk 0.36cvss 5.5epss 0.00
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
- risk 0.36cvss 5.5epss 0.00
An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.
- risk 0.36cvss 5.5epss 0.00
Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”
- risk 0.36cvss 5.5epss 0.00
Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.
- risk 0.36cvss 5.5epss 0.00
Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.
- risk 0.36cvss 5.5epss 0.00
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
- risk 0.36cvss 5.5epss 0.00
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.
Page 1 of 4