CVEs (88)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020...Show more |
3Debian FreedesktopRedhat3Debian Linux Enterprise LinuxPopplerJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash...Show more |
4Freedesktop OpensuseRedhat+1 more4Enterprise Linux OpensusePoppler+1 moreNov 21, 2024 Jan 9, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts. |
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. |
4Debian FedoraprojectFreedesktop+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Jul 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with...Show more |
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. |
2Fedoraproject Freedesktop2Fedora PopplerJun 17, 2026 Apr 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc. |
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc. |
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. |
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc. |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more |
3Debian FedoraprojectFreedesktop3Debian Linux FedoraPopplerJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. |
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It a...Show more |
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary....Show more |
3Canonical DebianFreedesktop3Debian Linux PopplerUbuntu LinuxJun 17, 2026 Feb 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to c...Show more |
5Canonical DebianFedoraproject+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreJun 17, 2026 Feb 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have un...Show more |
5Canonical DebianFedoraproject+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Jan 3, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in whi...Show more |