CVE-2018-8105
- EPSS 0.14%
- Veröffentlicht 14.03.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:16
The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
CVE-2018-8106
- EPSS 0.14%
- Veröffentlicht 14.03.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:16
The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
CVE-2018-8107
- EPSS 0.14%
- Veröffentlicht 14.03.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:16
The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
CVE-2018-7455
- EPSS 0.15%
- Veröffentlicht 24.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:10
An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
CVE-2018-7454
- EPSS 0.15%
- Veröffentlicht 24.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:09
A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
CVE-2018-7453
- EPSS 0.41%
- Veröffentlicht 24.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:09
Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.
CVE-2018-7452
- EPSS 0.14%
- Veröffentlicht 24.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:09
A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
CVE-2018-7175
- EPSS 0.18%
- Veröffentlicht 15.02.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:43
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
CVE-2018-7174
- EPSS 0.18%
- Veröffentlicht 15.02.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:43
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
CVE-2018-7173
- EPSS 0.15%
- Veröffentlicht 15.02.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:43
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.