← Back

Xpdfreader

xpdfreader

82 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Xpdf
xpdf

CVEs (82)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xpdfreader
1Xpdf
Oct 6, 2025
Aug 15, 2024
2.1 LOW· v4
8.2 HIGH· v3
N/A· v2
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
1Xpdfreader
1Xpdf
Aug 28, 2024
Aug 15, 2024
2.1 LOW· v4
6.2 MEDIUM· v3
N/A· v2
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
1Xpdfreader
1Xpdf
Aug 20, 2024
Aug 15, 2024
2.1 LOW· v4
5.5 MEDIUM· v3
N/A· v2
In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
1Xpdfreader
1Xpdf
Jan 29, 2025
May 15, 2024
2.1 LOW· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
1Xpdfreader
1Xpdf
Jan 29, 2025
May 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
1Xpdfreader
1Xpdf
Jan 29, 2025
Apr 24, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.
1Xpdfreader
1Xpdf
Jan 29, 2025
Apr 17, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
1Xpdfreader
1Xpdf
Jan 29, 2025
Apr 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.
1Xpdfreader
1Xpdf
Jan 29, 2025
Apr 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.
1Xpdfreader
1Xpdf
Jan 29, 2025
Mar 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.
1Xpdfreader
1Xpdf
Nov 21, 2024
Aug 22, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.
1Xpdfreader
1Xpdf
Nov 21, 2024
Jun 27, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.
1Xpdfreader
1Xpdf
Nov 21, 2024
Jun 2, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is cause...Show more
An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate. Show less
1Xpdfreader
1Xpdf
Nov 21, 2024
May 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.
1Xpdfreader
1Xpdf
Jan 24, 2025
May 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.
1Xpdfreader
1Xpdf
Jan 24, 2025
May 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
1Xpdfreader
1Xpdf
Nov 21, 2024
Apr 26, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”
1Xpdfreader
1Xpdf
Mar 19, 2025
Feb 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.
1Xpdfreader
1Xpdf
Mar 19, 2025
Feb 15, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.
1Xpdfreader
1Xpdf
Mar 27, 2025
Feb 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.