CVE-2020-27778
- EPSS 2.17%
- Veröffentlicht 03.12.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:49
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a deni...
CVE-2012-2142
- EPSS 2.94%
- Veröffentlicht 09.01.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:38:35
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
CVE-2010-4654
- EPSS 1.16%
- Veröffentlicht 13.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:21:27
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
CVE-2010-4653
- EPSS 1.82%
- Veröffentlicht 13.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:21:27
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
CVE-2018-21009
- EPSS 1.89%
- Veröffentlicht 05.09.2019 04:15:09
- Zuletzt bearbeitet 21.11.2024 04:02:41
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
CVE-2019-14494
- EPSS 2.68%
- Veröffentlicht 01.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:26:51
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
CVE-2019-9959
- EPSS 1.91%
- Veröffentlicht 22.07.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:40
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attac...
CVE-2019-12293
- EPSS 2.09%
- Veröffentlicht 23.05.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:34
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.
CVE-2019-11026
- EPSS 1.81%
- Veröffentlicht 08.04.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:23
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
CVE-2019-10873
- EPSS 2.65%
- Veröffentlicht 05.04.2019 04:29:01
- Zuletzt bearbeitet 21.11.2024 04:20:01
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.