Search CVE reports


Toggle filters

21 – 30 of 62 results


CVE-2018-5783

Medium priority
Needs evaluation

In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-5309

Medium priority
Needs evaluation

In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-5308

Medium priority

Some fixes available 4 of 15

PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Fixed Fixed Not affected
Show less packages

CVE-2018-5296

Medium priority
Needs evaluation

In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-5295

Medium priority
Vulnerable

In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-20797

Medium priority

Some fixes available 4 of 13

An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Fixed Fixed Fixed
Show less packages

CVE-2018-20751

Medium priority
Needs evaluation

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-19532

Medium priority
Vulnerable

A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-15889

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5783. Reason: This candidate is a reservation duplicate of CVE-2018-5783. Notes: All CVE users should reference CVE-2018-5783 instead of this candidate. All...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected
Show less packages

CVE-2018-14320

Medium priority
Needs evaluation

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation
Show less packages