Freedesktop

Poppler

97 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.34%
  • Veröffentlicht 22.06.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

Exploit
  • EPSS 1.14%
  • Veröffentlicht 06.06.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

  • EPSS 2.39%
  • Veröffentlicht 02.06.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.

  • EPSS 1.46%
  • Veröffentlicht 02.06.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.

  • EPSS 1.09%
  • Veröffentlicht 30.05.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.

Exploit
  • EPSS 1.12%
  • Veröffentlicht 19.05.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

  • EPSS 4.56%
  • Veröffentlicht 06.05.2016 17:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mo...

Exploit
  • EPSS 2.98%
  • Veröffentlicht 29.08.2014 16:55:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

  • EPSS 0.37%
  • Veröffentlicht 22.04.2014 14:23:34
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

  • EPSS 2.23%
  • Veröffentlicht 26.01.2014 01:55:13
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash...