CVE-2010-5110
- EPSS 0.78%
- Veröffentlicht 29.08.2014 16:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
CVE-2013-4472
- EPSS 0.07%
- Veröffentlicht 22.04.2014 14:23:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
- EPSS 2.48%
- Veröffentlicht 26.01.2014 01:55:13
- Zuletzt bearbeitet 11.04.2025 00:51:21
The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash...
- EPSS 29.76%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.
CVE-2013-4473
- EPSS 2.27%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.
CVE-2013-1790
- EPSS 2.98%
- Veröffentlicht 09.04.2013 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
CVE-2013-1789
- EPSS 2.85%
- Veröffentlicht 09.04.2013 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleM...
CVE-2013-1788
- EPSS 4.15%
- Veröffentlicht 09.04.2013 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/St...
CVE-2010-3702
- EPSS 3.86%
- Veröffentlicht 05.11.2010 18:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unkn...
CVE-2007-3387
- EPSS 8.74%
- Veröffentlicht 30.07.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute...