CVE-2021-40226
- EPSS 0.33%
- Published 10.11.2022 18:15:10
- Last modified 01.05.2025 18:15:46
xpdfreader 4.03 is vulnerable to Buffer Overflow.
CVE-2022-24107
- EPSS 0.08%
- Published 30.08.2022 04:15:10
- Last modified 21.11.2024 06:49:49
Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
CVE-2022-24106
- EPSS 0.11%
- Published 30.08.2022 04:15:10
- Last modified 21.11.2024 06:49:48
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
CVE-2019-17064
- EPSS 0.37%
- Published 01.10.2019 16:15:11
- Last modified 21.11.2024 04:31:38
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
CVE-2019-16115
- EPSS 0.18%
- Published 08.09.2019 22:15:11
- Last modified 21.11.2024 04:30:04
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows ...
CVE-2019-16088
- EPSS 0.32%
- Published 06.09.2019 22:15:11
- Last modified 21.11.2024 04:30:00
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
CVE-2019-15860
- EPSS 0.17%
- Published 03.09.2019 07:15:10
- Last modified 21.11.2024 04:29:37
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
CVE-2019-14289
- EPSS 0.17%
- Published 27.07.2019 19:15:11
- Last modified 21.11.2024 04:26:22
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.
CVE-2019-14288
- EPSS 0.2%
- Published 27.07.2019 19:15:11
- Last modified 21.11.2024 04:26:22
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
CVE-2019-14290
- EPSS 0.17%
- Published 27.07.2019 19:15:11
- Last modified 21.11.2024 04:26:23
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.