CVEs (53)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftot...Show more |
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jun 25, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a cra...Show more |
There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might...Show more |
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be t...Show more |
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It migh...Show more |
There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows...Show more |
There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Se...Show more |
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Serv...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Typ...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a craft...Show more |
4Foolabs GlyphandcogKde+1 more4Kdegraphics PopplerXpdf+1 moreApr 29, 2026 Nov 5, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attac...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of s...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to exe...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that trig...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-base...Show more |