Freedesktop

Poppler

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.71%
  • Veröffentlicht 23.05.2019 05:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:34

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

Exploit
  • EPSS 0.55%
  • Veröffentlicht 08.04.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:23

FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.

Exploit
  • EPSS 0.96%
  • Veröffentlicht 05.04.2019 04:29:01
  • Zuletzt bearbeitet 21.11.2024 04:20:01

An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

Exploit
  • EPSS 0.99%
  • Veröffentlicht 05.04.2019 04:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:00

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 05.04.2019 04:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:00

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

Exploit
  • EPSS 0.78%
  • Veröffentlicht 21.03.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:32

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.

  • EPSS 2.22%
  • Veröffentlicht 08.03.2019 05:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:00

Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 01.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:51:49

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Den...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 01.03.2019 19:29:02
  • Zuletzt bearbeitet 21.11.2024 04:51:49

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to caus...

Exploit
  • EPSS 5.48%
  • Veröffentlicht 26.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:51:11

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmen...