CVEs (88)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentati...Show more |
2Canonical Freedesktop2Poppler Ubuntu LinuxApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filenam...Show more |
2Canonical Freedesktop2Poppler Ubuntu LinuxApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source file...Show more |
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function. |
splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::bl...Show more |
poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/F...Show more |
9Apple CanonicalDebian+6 more11Cups Debian LinuxEnterprise Linux Desktop+8 moreApr 29, 2026 Nov 5, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more |
6Apple CanonicalDebian+3 more6Cups Debian LinuxGpdf+3 moreApr 23, 2026 Jul 30, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might all...Show more |