Xpdf

Xpdf

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.53%
  • Veröffentlicht 27.04.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

  • EPSS 3.39%
  • Veröffentlicht 27.01.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by C...

  • EPSS 4.44%
  • Veröffentlicht 27.01.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabili...

  • EPSS 7.31%
  • Veröffentlicht 10.01.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and...

  • EPSS 29.87%
  • Veröffentlicht 24.07.2003 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 02.01.2003 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.

  • EPSS 0.8%
  • Veröffentlicht 20.10.2000 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.

  • EPSS 0.05%
  • Veröffentlicht 20.10.2000 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.