CVE-2017-9775
- EPSS 4.34%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
CVE-2017-7515
- EPSS 1.14%
- Veröffentlicht 06.06.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
CVE-2017-9408
- EPSS 2.39%
- Veröffentlicht 02.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9406
- EPSS 1.46%
- Veröffentlicht 02.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-7511
- EPSS 1.09%
- Veröffentlicht 30.05.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.
CVE-2017-9083
- EPSS 1.12%
- Veröffentlicht 19.05.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.
CVE-2015-8868
- EPSS 4.56%
- Veröffentlicht 06.05.2016 17:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mo...
CVE-2010-5110
- EPSS 2.98%
- Veröffentlicht 29.08.2014 16:55:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
CVE-2013-4472
- EPSS 0.37%
- Veröffentlicht 22.04.2014 14:23:34
- Zuletzt bearbeitet 06.05.2026 22:30:45
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
- EPSS 2.23%
- Veröffentlicht 26.01.2014 01:55:13
- Zuletzt bearbeitet 29.04.2026 01:13:23
The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash...