← Back

Xpdfreader

xpdfreader

Vendor: Glyphandcog • 53 CVEs

CVEs (53)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Glyphandcog
1Xpdfreader
May 1, 2025
Nov 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
xpdfreader 4.03 is vulnerable to Buffer Overflow.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Aug 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Aug 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Oct 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Sep 8, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to...Show more
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact.Show less
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Sep 6, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Sep 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 27, 2019
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow...Show more
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.Show less
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
1Glyphandcog
1Xpdfreader
Nov 21, 2024
Jul 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdfto...Show more
In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to CVE-2018-16368.Show less
2Fedoraproject
Glyphandcog
2Fedora
Xpdfreader
Nov 21, 2024
Jul 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool...Show more
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.Show less
2Fedoraproject
Glyphandcog
2Fedora
Xpdfreader
Nov 21, 2024
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. I...Show more
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.Show less