Freedesktop

Poppler

97 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.94%
  • Veröffentlicht 20.09.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

Exploit
  • EPSS 1.54%
  • Veröffentlicht 17.09.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop).

Exploit
  • EPSS 1.06%
  • Veröffentlicht 17.09.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

Exploit
  • EPSS 1.21%
  • Veröffentlicht 17.09.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.

Exploit
  • EPSS 1.21%
  • Veröffentlicht 17.09.2017 23:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.

Exploit
  • EPSS 4.42%
  • Veröffentlicht 12.07.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resul...

  • EPSS 1.98%
  • Veröffentlicht 12.07.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacke...

  • EPSS 2.72%
  • Veröffentlicht 12.07.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to cod...

  • EPSS 1.68%
  • Veröffentlicht 25.06.2017 13:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in I...

  • EPSS 2%
  • Veröffentlicht 22.06.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.