Xpdf

Xpdf

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 02.04.2025 23:15:18
  • Zuletzt bearbeitet 07.04.2025 14:18:34

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

  • EPSS 0.02%
  • Veröffentlicht 20.03.2025 21:15:23
  • Zuletzt bearbeitet 06.10.2025 23:15:33

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

  • EPSS 2.45%
  • Veröffentlicht 21.12.2009 21:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers ...

  • EPSS 8.89%
  • Veröffentlicht 08.11.2007 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.

  • EPSS 3.92%
  • Veröffentlicht 08.11.2007 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.

  • EPSS 16.14%
  • Veröffentlicht 08.11.2007 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code v...

Exploit
  • EPSS 19.01%
  • Veröffentlicht 09.01.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite l...

  • EPSS 3.47%
  • Veröffentlicht 15.03.2006 19:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving error...

  • EPSS 4.38%
  • Veröffentlicht 09.03.2006 00:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.

  • EPSS 3.08%
  • Veröffentlicht 30.01.2006 22:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted...