Freedesktop

Poppler

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Veröffentlicht 05.05.2022 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:55:36

A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

Warnung
  • EPSS 72.86%
  • Veröffentlicht 24.08.2021 19:15:14
  • Zuletzt bearbeitet 27.10.2025 17:38:22

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code e...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 25.12.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:52

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 03.12.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:49

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a deni...

Exploit
  • EPSS 1.33%
  • Veröffentlicht 09.01.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 01:38:35

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

  • EPSS 0.47%
  • Veröffentlicht 13.11.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 01:21:27

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

  • EPSS 0.78%
  • Veröffentlicht 13.11.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 01:21:27

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

  • EPSS 0.36%
  • Veröffentlicht 05.09.2019 04:15:09
  • Zuletzt bearbeitet 21.11.2024 04:02:41

Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

Exploit
  • EPSS 1.97%
  • Veröffentlicht 01.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:26:51

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

  • EPSS 1.49%
  • Veröffentlicht 22.07.2019 15:15:10
  • Zuletzt bearbeitet 21.11.2024 04:52:40

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attac...