Freedesktop

Poppler

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 22.08.2023 19:16:23
  • Zuletzt bearbeitet 03.11.2025 20:15:55

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulner...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 22.08.2023 19:16:23
  • Zuletzt bearbeitet 03.11.2025 20:15:55

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 22.08.2023 19:16:23
  • Zuletzt bearbeitet 03.11.2025 20:15:55

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.08.2023 19:16:19
  • Zuletzt bearbeitet 21.11.2024 05:14:05

Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 22.08.2023 19:15:56
  • Zuletzt bearbeitet 21.11.2024 05:08:49

Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 11.08.2023 14:15:11
  • Zuletzt bearbeitet 03.11.2025 20:15:45

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 11.08.2023 14:15:11
  • Zuletzt bearbeitet 03.11.2025 20:15:45

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 31.07.2023 14:15:10
  • Zuletzt bearbeitet 04.11.2025 20:16:32

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.08.2022 03:15:07
  • Zuletzt bearbeitet 21.11.2024 07:17:04

Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary c...

  • EPSS 0.07%
  • Veröffentlicht 22.08.2022 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:15:56

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This i...