← Back

Freedesktop

freedesktop

150 CVEs • 23 products

Products (23)

Click to collapse
Toggle
Poppler
poppler
Dbus
dbus
Xdg Utils
xdg-utils
Udisks
udisks
Libinput
libinput
Policykit
policykit
Dbus Glib
dbus-glib
Libbsd
libbsd
Polkit
polkit
Dbus1.0
dbus1.0
Dbus1.1.0
dbus1.1.0
Scratchbox2
scratchbox2
Colord
colord
Libdbus
libdbus
Spice Gtk
spice-gtk
Virglrenderer
virglrenderer
Xdg User Dirs
xdg-user-dirs
Libice
libice

CVEs (150)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianFreedesktop+1 more
7Ansible Tower
Debian LinuxEnterprise Linux Desktop+4 more
Nov 21, 2024
May 6, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages suc...Show more
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.Show less
2Freedesktop
Redhat
2Enterprise Linux
Xdg User Dirs
Nov 21, 2024
Jan 9, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped...Show more
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.Show less
2Debian
Freedesktop
2Debian Linux
Poppler
Nov 21, 2024
Jan 2, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Oct 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Oct 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of servic...Show more
The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.Show less
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Oct 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a de...Show more
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.Show less
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Oct 2, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service...Show more
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.Show less
1Freedesktop
1Poppler
May 13, 2026
Sep 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx:...Show more
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.Show less
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Sep 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.
1Freedesktop
1Poppler
May 13, 2026
Sep 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Sep 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.
1Freedesktop
1Poppler
May 13, 2026
Sep 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.
1Freedesktop
1Poppler
May 13, 2026
Sep 17, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
1Freedesktop
1Poppler
May 13, 2026
Sep 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite...Show more
In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop).Show less
1Freedesktop
1Poppler
May 13, 2026
Sep 17, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
1Freedesktop
1Poppler
May 13, 2026
Sep 17, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
1Freedesktop
1Poppler
May 13, 2026
Jul 12, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memo...Show more
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary code execution. To trigger this vulnerability, a victim must open the malicious PDF in an application using this library.Show less
1Freedesktop
1Poppler
May 13, 2026
Jul 12, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting...Show more
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.Show less
1Freedesktop
1Poppler
May 13, 2026
Jul 12, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap co...Show more
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker controlled PDF file can be used to trigger this vulnerability.Show less
2Debian
Freedesktop
2Debian Linux
Poppler
May 13, 2026
Jun 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to mis...Show more
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.Show less