CVE-2005-0206
- EPSS 6.53%
- Veröffentlicht 27.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
- EPSS 3.39%
- Veröffentlicht 27.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by C...
- EPSS 4.44%
- Veröffentlicht 27.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabili...
CVE-2004-1125
- EPSS 7.31%
- Veröffentlicht 10.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and...
CVE-2003-0434
- EPSS 29.87%
- Veröffentlicht 24.07.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
CVE-2002-1384
- EPSS 0.07%
- Veröffentlicht 02.01.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
CVE-2000-0727
- EPSS 0.8%
- Veröffentlicht 20.10.2000 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.
CVE-2000-0728
- EPSS 0.05%
- Veröffentlicht 20.10.2000 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.