Freedesktop

Poppler

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.68%
  • Veröffentlicht 06.09.2018 23:29:01
  • Zuletzt bearbeitet 21.11.2024 03:53:08

In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.

  • EPSS 0.84%
  • Veröffentlicht 25.07.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:48:22

Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitab...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 10.05.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:43

The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

Exploit
  • EPSS 1.85%
  • Veröffentlicht 06.05.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:00

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are no...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 02.01.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:46

freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 17.10.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 02.10.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

Exploit
  • EPSS 1.09%
  • Veröffentlicht 02.10.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 02.10.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.

  • EPSS 0.47%
  • Veröffentlicht 30.09.2017 01:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc ...