CVE-2026-107705
- EPSS -
- Veröffentlicht 08.10.2026 19:51:12
- Zuletzt bearbeitet 08.10.2026 20:17:35
Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer th...
CVE-2026-102621
- EPSS 0.11%
- Veröffentlicht 29.09.2026 21:30:11
- Zuletzt bearbeitet 30.09.2026 20:17:22
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environm...
CVE-2026-102620
- EPSS 0.12%
- Veröffentlicht 29.09.2026 20:30:15
- Zuletzt bearbeitet 02.10.2026 13:17:16
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The ...
CVE-2026-93314
- EPSS 0.25%
- Veröffentlicht 18.09.2026 01:30:10
- Zuletzt bearbeitet 22.09.2026 03:16:58
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be laun...
- EPSS 0.34%
- Veröffentlicht 18.09.2026 01:16:56
- Zuletzt bearbeitet 22.09.2026 19:16:57
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has ...
- EPSS 0.32%
- Veröffentlicht 18.09.2026 01:16:56
- Zuletzt bearbeitet 22.09.2026 16:18:13
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in ...
CVE-2026-93313
- EPSS 0.25%
- Veröffentlicht 18.09.2026 01:15:13
- Zuletzt bearbeitet 18.09.2026 13:23:37
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remote...
CVE-2025-43718
- EPSS 0.13%
- Veröffentlicht 01.10.2025 19:15:35
- Zuletzt bearbeitet 30.09.2026 23:10:00
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Di...
CVE-2025-50420
- EPSS 0.3%
- Veröffentlicht 04.08.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 16:19:29
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).
CVE-2025-50422
- EPSS 0.21%
- Veröffentlicht 04.08.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.