Glyphandcog
glyphandcog
55 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (55)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. I...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftot...Show more |
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderNov 21, 2024 Jun 25, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a cra...Show more |
There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might...Show more |
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be t...Show more |
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It migh...Show more |
There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows...Show more |
There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Se...Show more |
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Serv...Show more |
2Debian Glyphandcog2Debian Linux XpdfNov 21, 2024 Jan 30, 2018 N/A· v4 5.3 MEDIUM· v3 6.4 MEDIUM· v2 zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pd...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Typ...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a craft...Show more |
4Foolabs GlyphandcogKde+1 more4Kdegraphics PopplerXpdf+1 moreApr 29, 2026 Nov 5, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attac...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of s...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to exe...Show more |
3Foolabs GlyphandcogPoppler3Poppler XpdfXpdfreaderApr 23, 2026 Oct 21, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that trig...Show more |