CVE-2022-43071
- EPSS 0.1%
- Veröffentlicht 15.11.2022 17:15:11
- Zuletzt bearbeitet 30.04.2025 18:15:35
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-43295
- EPSS 0.07%
- Veröffentlicht 14.11.2022 21:15:21
- Zuletzt bearbeitet 13.05.2025 20:15:23
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
CVE-2022-41844
- EPSS 0.08%
- Veröffentlicht 30.09.2022 05:15:11
- Zuletzt bearbeitet 20.05.2025 20:15:26
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
CVE-2022-41843
- EPSS 0.11%
- Veröffentlicht 30.09.2022 05:15:11
- Zuletzt bearbeitet 20.05.2025 20:15:26
An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.
CVE-2022-41842
- EPSS 0.44%
- Veröffentlicht 30.09.2022 05:15:11
- Zuletzt bearbeitet 20.05.2025 20:15:26
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
CVE-2022-38222
- EPSS 0.1%
- Veröffentlicht 29.09.2022 03:15:15
- Zuletzt bearbeitet 21.11.2024 07:16:05
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have...
CVE-2022-38928
- EPSS 0.13%
- Veröffentlicht 21.09.2022 13:15:09
- Zuletzt bearbeitet 27.05.2025 19:15:22
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
CVE-2022-38334
- EPSS 0.1%
- Veröffentlicht 15.09.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:16:16
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
CVE-2022-36561
- EPSS 0.06%
- Veröffentlicht 30.08.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:13:18
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
CVE-2022-38171
- EPSS 0.07%
- Veröffentlicht 22.08.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:15:56
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This i...