CVE-2025-43718
- EPSS 0.02%
- Published 01.10.2025 19:15:35
- Last modified 06.10.2025 18:15:51
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Di...
CVE-2025-52886
- EPSS 0.02%
- Published 02.07.2025 15:46:49
- Last modified 03.07.2025 15:13:53
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patche...
CVE-2024-56378
- EPSS 0.29%
- Published 23.12.2024 00:15:05
- Last modified 26.12.2024 20:15:23
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
CVE-2010-3704
- EPSS 1.53%
- Published 05.11.2010 18:00:25
- Last modified 11.04.2025 00:51:21
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of serv...
CVE-2010-3703
- EPSS 1.14%
- Published 05.11.2010 18:00:25
- Last modified 11.04.2025 00:51:21
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (cras...
CVE-2009-3938
- EPSS 3.45%
- Published 13.11.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial...
CVE-2009-3605
- EPSS 4.39%
- Published 02.11.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (...
CVE-2009-3609
- EPSS 5.3%
- Published 21.10.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via...
CVE-2009-3608
- EPSS 6.22%
- Published 21.10.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a craf...
CVE-2009-3607
- EPSS 6.86%
- Published 21.10.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that tri...