Poppler

Poppler

30 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.96%
  • Published 23.04.2009 17:30:01
  • Last modified 09.04.2025 00:30:58

Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.

  • EPSS 0.68%
  • Published 23.04.2009 17:30:01
  • Last modified 09.04.2025 00:30:58

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.

  • EPSS 5.54%
  • Published 23.04.2009 17:30:01
  • Last modified 09.04.2025 00:30:58

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.

Exploit
  • EPSS 13.98%
  • Published 03.03.2009 16:30:05
  • Last modified 09.04.2025 00:30:58

The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and tri...

Exploit
  • EPSS 23.19%
  • Published 03.03.2009 16:30:05
  • Last modified 09.04.2025 00:30:58

The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.

  • EPSS 12.44%
  • Published 07.07.2008 23:41:00
  • Last modified 09.04.2025 00:30:58

The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.

  • EPSS 6.65%
  • Published 18.04.2008 15:05:00
  • Last modified 09.04.2025 00:30:58

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute a...

Exploit
  • EPSS 7.36%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...

Exploit
  • EPSS 9.33%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.

Exploit
  • EPSS 11.29%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...