CVE-2024-24246
- EPSS 0.22%
- Published 29.02.2024 20:15:41
- Last modified 21.11.2024 08:59:03
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
CVE-2021-25786
- EPSS 0.3%
- Published 11.08.2023 14:15:11
- Last modified 21.11.2024 05:55:26
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
CVE-2022-34503
- EPSS 0.33%
- Published 22.07.2022 15:15:08
- Last modified 21.11.2024 07:09:41
QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2021-36978
- EPSS 0.08%
- Published 20.07.2021 07:15:08
- Last modified 21.11.2024 06:14:25
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
CVE-2018-18020
- EPSS 0.11%
- Published 06.10.2018 14:29:00
- Last modified 21.11.2024 03:55:23
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
CVE-2018-9918
- EPSS 0.24%
- Published 10.04.2018 18:29:00
- Last modified 21.11.2024 04:15:50
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, beca...
CVE-2017-18183
- EPSS 0.32%
- Published 13.02.2018 19:29:00
- Last modified 21.11.2024 03:19:30
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
CVE-2017-18186
- EPSS 0.32%
- Published 13.02.2018 19:29:00
- Last modified 21.11.2024 03:19:30
An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.
CVE-2017-18185
- EPSS 0.16%
- Published 13.02.2018 19:29:00
- Last modified 21.11.2024 03:19:30
An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.
CVE-2017-18184
- EPSS 0.1%
- Published 13.02.2018 19:29:00
- Last modified 21.11.2024 03:19:30
An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.