CVE-2017-14617
- EPSS 0.94%
- Veröffentlicht 20.09.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.
CVE-2017-14519
- EPSS 1.54%
- Veröffentlicht 17.09.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop).
CVE-2017-14517
- EPSS 1.06%
- Veröffentlicht 17.09.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
CVE-2017-14518
- EPSS 1.21%
- Veröffentlicht 17.09.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
CVE-2017-14520
- EPSS 1.21%
- Veröffentlicht 17.09.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
CVE-2017-2820
- EPSS 4.42%
- Veröffentlicht 12.07.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resul...
CVE-2017-2818
- EPSS 1.98%
- Veröffentlicht 12.07.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacke...
CVE-2017-2814
- EPSS 2.72%
- Veröffentlicht 12.07.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to cod...
CVE-2017-9865
- EPSS 1.68%
- Veröffentlicht 25.06.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in I...
CVE-2017-9776
- EPSS 2%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.