Search CVE reports


Toggle filters

21 – 30 of 203 results


CVE-2020-35376

Medium priority
Needs evaluation

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

3 affected packages

ipe, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
poppler Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2020-27778

Low priority
Fixed

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Fixed
Show less packages

CVE-2020-25725

Medium priority
Needs evaluation

In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3...

3 affected packages

poppler, ipe, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2020-24999

Medium priority
Needs evaluation

There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service...

3 affected packages

poppler, ipe, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2020-24996

Medium priority
Needs evaluation

There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a...

3 affected packages

poppler, ipe, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2020-23804

Medium priority
Fixed

Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Fixed Fixed
Show less packages

CVE-2020-18839

Medium priority
Not affected

Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected
Show less packages

CVE-2019-9959

Low priority

Some fixes available 2 of 15

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size...

2 affected packages

emscripten, poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
emscripten Ignored Ignored Not in release Ignored
poppler Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-9903

Low priority
Fixed

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2019-9878

Medium priority
Ignored

There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops...

4 affected packages

ipe, libextractor, xpdf, poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Not affected Not affected Not affected
libextractor Not affected Not affected Not affected
xpdf Not affected Not in release Not affected
poppler Not affected Not affected Not affected
Show less packages