Glyphandcog

Xpdfreader

53 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Published 10.11.2022 18:15:10
  • Last modified 01.05.2025 18:15:46

xpdfreader 4.03 is vulnerable to Buffer Overflow.

  • EPSS 0.08%
  • Published 30.08.2022 04:15:10
  • Last modified 21.11.2024 06:49:49

Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

  • EPSS 0.11%
  • Published 30.08.2022 04:15:10
  • Last modified 21.11.2024 06:49:48

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

Exploit
  • EPSS 0.37%
  • Published 01.10.2019 16:15:11
  • Last modified 21.11.2024 04:31:38

Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.

Exploit
  • EPSS 0.18%
  • Published 08.09.2019 22:15:11
  • Last modified 21.11.2024 04:30:04

In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows ...

Exploit
  • EPSS 0.32%
  • Published 06.09.2019 22:15:11
  • Last modified 21.11.2024 04:30:00

Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.

Exploit
  • EPSS 0.17%
  • Published 03.09.2019 07:15:10
  • Last modified 21.11.2024 04:29:37

Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

Exploit
  • EPSS 0.17%
  • Published 27.07.2019 19:15:11
  • Last modified 21.11.2024 04:26:22

An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.

Exploit
  • EPSS 0.2%
  • Published 27.07.2019 19:15:11
  • Last modified 21.11.2024 04:26:22

An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.

Exploit
  • EPSS 0.17%
  • Published 27.07.2019 19:15:11
  • Last modified 21.11.2024 04:26:23

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.