← Back

Evince

evince

Vendor: Gnome • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
GnomeOpensuse+1 more
4Debian Linux
Enterprise LinuxEvince+1 more
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
evince is missing a check on number of pages which can lead to a segmentation fault
4Canonical
DebianGnome+1 more
4Debian Linux
EvinceLeap+1 more
Nov 21, 2024
Jul 15, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs beca...Show more
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.Show less
6Canonical
DebianFedoraproject+3 more
9Debian Linux
Enterprise LinuxEnterprise Linux Eus+6 more
Nov 21, 2024
Apr 22, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory u...Show more
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.Show less
1Gnome
1Evince
May 13, 2026
Nov 27, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
3Debian
GnomeRedhat
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 13, 2026
Sep 5, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with...Show more
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.Show less
3Gnome
T1libTetex
3Evince
T1libTetex
Apr 29, 2026
Nov 19, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a de...Show more
Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.Show less
3Gnome
T1libTetex
3Evince
T1libTetex
Apr 29, 2026
Nov 19, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly ex...Show more
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.Show less