Freedesktop

Poppler

97 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.48%
  • Veröffentlicht 23.11.2013 11:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.

Exploit
  • EPSS 7.13%
  • Veröffentlicht 23.11.2013 11:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.

Exploit
  • EPSS 2.58%
  • Veröffentlicht 09.04.2013 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.

Exploit
  • EPSS 2.38%
  • Veröffentlicht 09.04.2013 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleM...

Exploit
  • EPSS 3.87%
  • Veröffentlicht 09.04.2013 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/St...

  • EPSS 2.76%
  • Veröffentlicht 05.11.2010 18:00:05
  • Zuletzt bearbeitet 16.06.2026 23:23:22

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unkn...

  • EPSS 8.57%
  • Veröffentlicht 30.07.2007 23:17:00
  • Zuletzt bearbeitet 16.06.2026 22:41:54

Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute...