9.3

CVE-2009-3604

Exploit

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FoolabsXpdf Version3.02pl1
   GnomeGpdf
   KdeKpdf
FoolabsXpdf Version3.02pl2
   GnomeGpdf
   KdeKpdf
FoolabsXpdf Version3.02pl3
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version2.00
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version2.01
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version2.02
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version2.03
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version3.00
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version3.01
   GnomeGpdf
   KdeKpdf
GlyphandcogXpdfreader Version3.02
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.1.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.1.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.2.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.3.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.3.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.3.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.3.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.4.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.4.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.4.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.4.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.4.4
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.4
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.9
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.90
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.5.91
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.6.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.6.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.6.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.6.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.6.4
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.7.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.7.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.7.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.7.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.4
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.5
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.6
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.8.7
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.9.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.9.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.9.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.9.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.4
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.5
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.6
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.10.7
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.11.0
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.11.1
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.11.2
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.11.3
   GnomeGpdf
   KdeKpdf
PopplerPoppler Version0.12.0
   GnomeGpdf
   KdeKpdf
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.74% 0.926
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C