CVE-2005-3193
- EPSS 4.08%
- Veröffentlicht 07.12.2005 00:03:00
- Zuletzt bearbeitet 16.06.2026 22:16:28
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-...
CVE-2005-2097
- EPSS 0.43%
- Veröffentlicht 16.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:14
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when ...
CVE-2005-0064
- EPSS 7.22%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:10:26
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
CVE-2005-0206
- EPSS 2.99%
- Veröffentlicht 27.04.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:10:41
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
- EPSS 6.21%
- Veröffentlicht 27.01.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:06:36
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by C...
- EPSS 9.33%
- Veröffentlicht 27.01.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:06:36
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabili...
CVE-2004-1125
- EPSS 6.58%
- Veröffentlicht 10.01.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:04
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and...
CVE-2003-0434
- EPSS 40.94%
- Veröffentlicht 24.07.2003 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:02:11
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
CVE-2002-1384
- EPSS 0.69%
- Veröffentlicht 02.01.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:59:13
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
CVE-2000-0727
- EPSS 2.56%
- Veröffentlicht 20.10.2000 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:52:21
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.