Freedesktop

Poppler

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 01.10.2025 19:15:35
  • Zuletzt bearbeitet 06.10.2025 18:15:51

Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Di...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 04.08.2025 00:00:00
  • Zuletzt bearbeitet 09.10.2025 17:43:54

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

  • EPSS 0.02%
  • Veröffentlicht 04.08.2025 00:00:00
  • Zuletzt bearbeitet 26.08.2025 19:15:44

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.07.2025 15:46:49
  • Zuletzt bearbeitet 04.11.2025 22:16:20

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patche...

  • EPSS 0.01%
  • Veröffentlicht 18.04.2025 21:15:44
  • Zuletzt bearbeitet 06.10.2025 16:37:14

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.04.2025 22:15:19
  • Zuletzt bearbeitet 03.11.2025 20:18:26

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 05.04.2025 22:15:18
  • Zuletzt bearbeitet 03.11.2025 20:18:26

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 23.12.2024 00:15:05
  • Zuletzt bearbeitet 03.11.2025 20:16:51

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

  • EPSS 0.13%
  • Veröffentlicht 21.06.2024 14:15:14
  • Zuletzt bearbeitet 21.11.2024 09:49:15

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 22.08.2023 19:16:23
  • Zuletzt bearbeitet 03.11.2025 20:15:55

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.