CVE-2025-52886
- EPSS 0.38%
- Veröffentlicht 02.07.2025 15:46:49
- Zuletzt bearbeitet 04.11.2025 22:16:20
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patche...
CVE-2025-43903
- EPSS 0.11%
- Veröffentlicht 18.04.2025 21:15:44
- Zuletzt bearbeitet 06.10.2025 16:37:14
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
CVE-2025-32365
- EPSS 0.23%
- Veröffentlicht 05.04.2025 22:15:19
- Zuletzt bearbeitet 03.11.2025 20:18:26
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
CVE-2025-32364
- EPSS 0.23%
- Veröffentlicht 05.04.2025 22:15:18
- Zuletzt bearbeitet 03.11.2025 20:18:26
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.
CVE-2024-56378
- EPSS 0.64%
- Veröffentlicht 23.12.2024 00:15:05
- Zuletzt bearbeitet 03.11.2025 20:16:51
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
CVE-2024-6239
- EPSS 0.79%
- Veröffentlicht 21.06.2024 14:15:14
- Zuletzt bearbeitet 21.11.2024 09:49:15
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.
CVE-2022-38349
- EPSS 0.91%
- Veröffentlicht 22.08.2023 19:16:23
- Zuletzt bearbeitet 03.11.2025 20:15:55
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
CVE-2022-37052
- EPSS 0.91%
- Veröffentlicht 22.08.2023 19:16:23
- Zuletzt bearbeitet 03.11.2025 20:15:55
A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
CVE-2022-37051
- EPSS 0.97%
- Veröffentlicht 22.08.2023 19:16:23
- Zuletzt bearbeitet 03.11.2025 20:15:55
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
CVE-2022-37050
- EPSS 0.93%
- Veröffentlicht 22.08.2023 19:16:23
- Zuletzt bearbeitet 03.11.2025 20:15:55
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulner...