Search CVE reports
21 – 30 of 203 results
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
3 affected packages
ipe, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
poppler | Not affected | Not affected | Not affected | Not affected |
xpdf | Not affected | Not affected | Not in release | Not affected |
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the...
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | — | — | Not affected | Fixed |
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3...
3 affected packages
poppler, ipe, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | Not affected | Not affected | Not affected | Not affected |
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
xpdf | Not affected | Not affected | Not in release | Not affected |
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service...
3 affected packages
poppler, ipe, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | Not affected | Not affected | Not affected | Not affected |
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
xpdf | Not affected | Not affected | Not in release | Not affected |
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a...
3 affected packages
poppler, ipe, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | Not affected | Not affected | Not affected | Not affected |
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
xpdf | Not affected | Not affected | Not in release | Not affected |
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | — | Not affected | Fixed | Fixed |
Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | — | Not affected | Not affected | Not affected |
Some fixes available 2 of 15
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size...
2 affected packages
emscripten, poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
emscripten | Ignored | Ignored | Not in release | Ignored |
poppler | Not affected | Not affected | Not affected | Fixed |
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the...
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
poppler | — | — | — | Fixed |
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops...
4 affected packages
ipe, libextractor, xpdf, poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ipe | — | Not affected | Not affected | Not affected |
libextractor | — | Not affected | Not affected | Not affected |
xpdf | — | Not affected | Not in release | Not affected |
poppler | — | Not affected | Not affected | Not affected |