← Back

Xpdfreader

xpdfreader

82 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Xpdf
xpdf

CVEs (82)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xpdfreader
1Xpdf
Apr 30, 2025
Nov 15, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
1Xpdfreader
1Xpdf
May 13, 2025
Nov 14, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
1Xpdfreader
1Xpdf
May 20, 2025
Sep 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
1Xpdfreader
1Xpdf
May 20, 2025
Sep 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.
1Xpdfreader
1Xpdf
May 20, 2025
Sep 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
1Xpdfreader
1Xpdf
Nov 21, 2024
Sep 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Deni...Show more
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.Show less
1Xpdfreader
1Xpdf
May 27, 2025
Sep 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
1Xpdfreader
1Xpdf
Nov 21, 2024
Sep 15, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
1Xpdfreader
1Xpdf
Nov 21, 2024
Aug 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
2Freedesktop
Xpdfreader
2Poppler
Xpdf
Nov 21, 2024
Aug 22, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execu...Show more
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).Show less
1Xpdfreader
1Xpdf
Nov 21, 2024
Jun 28, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
1Xpdfreader
1Xpdf
Nov 21, 2024
May 18, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
1Xpdfreader
1Xpdf
Nov 21, 2024
May 16, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPI...Show more
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.Show less
1Xpdfreader
1Xpdf
Nov 21, 2024
May 9, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pd...Show more
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.Show less
1Xpdfreader
1Xpdf
Nov 21, 2024
Apr 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PD...Show more
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.Show less
3Apple
FreedesktopXpdfreader
7Ipados
Iphone OsMac Os X+4 more
Oct 27, 2025
Aug 24, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PD...Show more
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.Show less
2Fedoraproject
Xpdfreader
2Fedora
Xpdf
Nov 21, 2024
Dec 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
2Fedoraproject
Xpdfreader
2Fedora
Xpdf
Nov 21, 2024
Nov 21, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested...Show more
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font.Show less
1Xpdfreader
1Xpdf
Nov 21, 2024
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of...Show more
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.Show less
1Xpdfreader
1Xpdf
Nov 21, 2024
Sep 3, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a rem...Show more
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.Show less