Xpdf

Xpdf

28 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 02.04.2025 23:15:18
  • Last modified 07.04.2025 14:18:34

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

  • EPSS 0.02%
  • Published 20.03.2025 21:15:23
  • Last modified 06.10.2025 23:15:33

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

  • EPSS 2.45%
  • Published 21.12.2009 21:30:00
  • Last modified 09.04.2025 00:30:58

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers ...

  • EPSS 8.89%
  • Published 08.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.

  • EPSS 3.92%
  • Published 08.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.

  • EPSS 16.14%
  • Published 08.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code v...

Exploit
  • EPSS 19.01%
  • Published 09.01.2007 00:28:00
  • Last modified 09.04.2025 00:30:58

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite l...

  • EPSS 3.47%
  • Published 15.03.2006 19:06:00
  • Last modified 03.04.2025 01:03:51

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving error...

  • EPSS 4.38%
  • Published 09.03.2006 00:02:00
  • Last modified 03.04.2025 01:03:51

Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.

  • EPSS 3.08%
  • Published 30.01.2006 22:03:00
  • Last modified 03.04.2025 01:03:51

Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted...