- EPSS 0.03%
- Veröffentlicht 19.03.2026 15:53:38
- Zuletzt bearbeitet 20.03.2026 13:39:46
A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.
- EPSS 0.01%
- Veröffentlicht 10.02.2026 10:02:09
- Zuletzt bearbeitet 10.02.2026 15:22:54
A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack i...
CVE-2026-25556
- EPSS 0.02%
- Veröffentlicht 06.02.2026 16:11:59
- Zuletzt bearbeitet 24.02.2026 21:07:13
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pix...
CVE-2025-55780
- EPSS 0.06%
- Veröffentlicht 23.09.2025 18:15:34
- Zuletzt bearbeitet 08.10.2025 18:04:01
A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->ne...
CVE-2025-46206
- EPSS 0.24%
- Veröffentlicht 04.08.2025 00:00:00
- Zuletzt bearbeitet 02.10.2025 17:39:43
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, th...
CVE-2024-46657
- EPSS 0.05%
- Veröffentlicht 10.12.2024 17:15:10
- Zuletzt bearbeitet 01.07.2025 13:39:18
Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2024-24259
- EPSS 0.25%
- Veröffentlicht 05.02.2024 18:15:52
- Zuletzt bearbeitet 04.11.2025 19:16:56
freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.
CVE-2024-24258
- EPSS 0.25%
- Veröffentlicht 05.02.2024 18:15:52
- Zuletzt bearbeitet 04.11.2025 19:16:56
freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.
CVE-2023-51107
- EPSS 0.07%
- Veröffentlicht 26.12.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:37:51
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a...
CVE-2023-51106
- EPSS 0.06%
- Veröffentlicht 26.12.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:37:51
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.