Записи Freedesktop
150 опубликованных записей вендора freedesktop.
Профиль для исследователя
- Попали в KEV
- 1 · 0,7 %
- С эксплойтом
- 1 · 0,7 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 90,7 %
- Медиана: публикация → KEV
- 71 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation19
- CWE-476 NULL Pointer Dereference16
- CWE-125 Out-of-bounds Read13
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer12
- CWE-190 Integer Overflow or Wraparound11
- CWE-674 Uncontrolled Recursion6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
150 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
84Срочно | CVE-2021-30860Готовый эксплойт | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | Высокая7,8 | KEV | 76,0 % | 24 авг. 2021 г. |
40В плане | CVE-2019-9631Эксплойта нет | Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.freedesktop · poppler · CWE-125 | Критическая9,8 | — | 3,5 % | 8 мар. 2019 г. |
40В плане | CVE-2016-2090Эксплойта нет | Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whifedoraproject · fedora · CWE-119 | Критическая9,8 | — | 3,2 % | 13 янв. 2017 г. |
40В плане | CVE-2021-3185Эксплойта нет | A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could causefreedesktop · gst-plugins-bad · CWE-120 | Критическая9,8 | — | 2,4 % | 26 янв. 2021 г. |
39Наблюдать | CVE-2026-50292Эксплойта нет | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrfreedesktop · libinput · CWE-93 | Критическая9,8 | — | 0,5 % | 4 июн. 2026 г. |
37Наблюдать | CVE-2019-20367Эксплойта нет | nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).freedesktop · libbsd · CWE-125 | Критическая9,1 | — | 2,8 % | 8 янв. 2020 г. |
36Наблюдать | CVE-2017-2820Эксплойта нет | An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.freedesktop · poppler · CWE-190 | Высокая8,8 | — | 4,4 % | 12 июл. 2017 г. |
36Наблюдать | CVE-2019-9200Эксплойта нет | A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered bfreedesktop · poppler · CWE-787 | Высокая8,8 | — | 3,5 % | 26 февр. 2019 г. |
36Наблюдать | CVE-2019-9543Эксплойта нет | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | Высокая8,8 | — | 3,3 % | 1 мар. 2019 г. |
36Наблюдать | CVE-2015-1877Эксплойта нет | The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, debian · debian linux · CWE-77 | Высокая8,8 | — | 3,2 % | 2 июн. 2021 г. |
36Наблюдать | CVE-2017-2814Эксплойта нет | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.freedesktop · poppler · CWE-119 | Высокая8,8 | — | 2,7 % | 12 июл. 2017 г. |
36Наблюдать | CVE-2019-10872Эксплойта нет | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-125 | Высокая8,8 | — | 2,7 % | 5 апр. 2019 г. |
36Наблюдать | CVE-2017-18266Эксплойта нет | The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSfreedesktop · xdg-utils · CWE-74 | Высокая8,8 | — | 2,5 % | 10 мая 2018 г. |
36Наблюдать | CVE-2019-12293Эксплойта нет | In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heightsfreedesktop · poppler · CWE-125 | Высокая8,8 | — | 2,1 % | 23 мая 2019 г. |
36Наблюдать | CVE-2017-15565Эксплойта нет | In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF documefreedesktop · poppler · CWE-476 | Высокая8,8 | — | 2,1 % | 17 окт. 2017 г. |
36Наблюдать | CVE-2017-2818Эксплойта нет | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.freedesktop · poppler · CWE-119 | Высокая8,8 | — | 2,0 % | 12 июл. 2017 г. |
36Наблюдать | CVE-2017-1000456Эксплойта нет | freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.freedesktop · poppler · CWE-119 | Высокая8,8 | — | 2,0 % | 2 янв. 2018 г. |
36Наблюдать | CVE-2018-21009Эксплойта нет | Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.freedesktop · poppler · CWE-190 | Высокая8,8 | — | 1,9 % | 5 сент. 2019 г. |
36Наблюдать | CVE-2019-9545Эксплойта нет | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | Высокая8,8 | — | 1,8 % | 1 мар. 2019 г. |
36Наблюдать | CVE-2026-46470Эксплойта нет | An issue was discovered in GStreamer gst-plugins-good before 1.28.2.freedesktop · gst-plugins-good · CWE-369 | Критическая9,1 | — | 0,4 % | 14 мая 2026 г. |
35Наблюдать | CVE-2026-35093Эксплойта нет | Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode pluginsfreedesktop · libinput · CWE-94 | Высокая8,8 | — | 0,2 % | 1 апр. 2026 г. |
32Наблюдать | CVE-2013-4473Эксплойта нет | Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause afreedesktop · poppler · CWE-119 | Высокая7,5 | — | 7,1 % | 23 нояб. 2013 г. |
32Наблюдать | CVE-2015-8868Эксплойта нет | Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to causfedoraproject · fedora · CWE-119 | Высокая7,8 | — | 4,6 % | 6 мая 2016 г. |
32Наблюдать | CVE-2012-2142Эксплойта нет | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapefreedesktop · poppler | Высокая7,8 | — | 2,9 % | 9 янв. 2020 г. |
32Наблюдать | CVE-2019-7310Эксплойта нет | In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remotfreedesktop · poppler · CWE-125 | Высокая7,8 | — | 2,1 % | 2 февр. 2019 г. |
- CVE-2021-3086084Срочно
An integer overflow was addressed with improved input validation.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 76 %apple · ipados24 авг. 2021 г.
- CVE-2019-963140В плане
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freedesktop · poppler8 мар. 2019 г.
- CVE-2016-209040В плане
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whi
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %fedoraproject · fedora13 янв. 2017 г.
- CVE-2021-318540В плане
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %freedesktop · gst-plugins-bad26 янв. 2021 г.
- CVE-2026-5029239Наблюдать
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %freedesktop · libinput4 июн. 2026 г.
- CVE-2019-2036737Наблюдать
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %freedesktop · libbsd8 янв. 2020 г.
- CVE-2017-282036Наблюдать
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %freedesktop · poppler12 июл. 2017 г.
- CVE-2019-920036Наблюдать
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered b
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %freedesktop · poppler26 февр. 2019 г.
- CVE-2019-954336Наблюдать
An issue was discovered in Poppler 0.74.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %freedesktop · poppler1 мар. 2019 г.
- CVE-2015-187736Наблюдать
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables,
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %debian · debian linux2 июн. 2021 г.
- CVE-2017-281436Наблюдать
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %freedesktop · poppler12 июл. 2017 г.
- CVE-2019-1087236Наблюдать
An issue was discovered in Poppler 0.74.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %freedesktop · poppler5 апр. 2019 г.
- CVE-2017-1826636Наблюдать
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWS
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · xdg-utils10 мая 2018 г.
- CVE-2019-1229336Наблюдать
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler23 мая 2019 г.
- CVE-2017-1556536Наблюдать
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF docume
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler17 окт. 2017 г.
- CVE-2017-281836Наблюдать
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler12 июл. 2017 г.
- CVE-2017-100045636Наблюдать
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler2 янв. 2018 г.
- CVE-2018-2100936Наблюдать
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler5 сент. 2019 г.
- CVE-2019-954536Наблюдать
An issue was discovered in Poppler 0.74.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freedesktop · poppler1 мар. 2019 г.
- CVE-2026-4647036Наблюдать
An issue was discovered in GStreamer gst-plugins-good before 1.28.2.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %freedesktop · gst-plugins-good14 мая 2026 г.
- CVE-2026-3509335Наблюдать
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %freedesktop · libinput1 апр. 2026 г.
- CVE-2013-447332Наблюдать
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %freedesktop · poppler23 нояб. 2013 г.
- CVE-2015-886832Наблюдать
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to caus
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %fedoraproject · fedora6 мая 2016 г.
- CVE-2012-214232Наблюдать
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %freedesktop · poppler9 янв. 2020 г.
- CVE-2019-731032Наблюдать
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remot
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %freedesktop · poppler2 февр. 2019 г.