Freedesktop
freedesktop
150 CVEs • 23 products
Products (23)
Click to collapseToggle
Products (23)
Click to collapse
CVEs (150)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020...Show more |
3Debian FreedesktopRedhat3Debian Linux Enterprise LinuxPopplerJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash...Show more |
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an inf...Show more |
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stoppi...Show more |
2Canonical Freedesktop2Dbus Ubuntu LinuxJun 17, 2026 Jun 8, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with acces...Show more |
4Freedesktop OpensuseRedhat+1 more4Enterprise Linux OpensusePoppler+1 moreNov 21, 2024 Jan 9, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. |
4Canonical DebianFreedesktop+1 more4Debian Linux LeapLibbsd+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab). |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts. |
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. |
4Debian FedoraprojectFreedesktop+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Jul 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with...Show more |
2Canonical Freedesktop2Dbus Ubuntu LinuxJun 17, 2026 Jun 11, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink...Show more |
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. |
2Fedoraproject Freedesktop2Fedora PopplerJun 17, 2026 Apr 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc. |
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc. |
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. |
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc. |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more |
3Debian FedoraprojectFreedesktop3Debian Linux FedoraPopplerJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. |