Xpdf kayıtları
xpdf üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 17
- Düzeltme kaydı olan
- %92,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-20 Improper Input Validation2
- CWE-399 Resource Management Errors2
- CWE-189 Numeric Errors1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2004-0888İstismar yok | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Kritik10,0 | — | %9,5 | 27 Oca 2005 |
42Planlayın | CVE-2003-0434Kavram kanıtı | Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metachadobe · acrobat | Yüksek7,5 | — | %40,9 | 24 Tem 2003 |
42Planlayın | CVE-2004-0889İstismar yok | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Kritik10,0 | — | %6,2 | 27 Oca 2005 |
41Planlayın | CVE-2005-3625İstismar yok | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Kritik10,0 | — | %3,8 | 31 Ara 2005 |
39İzleyin | CVE-2004-1125İstismar yok | Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3xpdf · xpdf · CWE-20 | Kritik9,3 | — | %6,6 | 10 Oca 2005 |
39İzleyin | CVE-2007-5393İstismar yok | Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitxpdf · xpdf · CWE-119 | Kritik9,3 | — | %6,4 | 7 Kas 2007 |
39İzleyin | CVE-2007-5392İstismar yok | Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crxpdf · xpdf · CWE-119 | Kritik9,3 | — | %6,4 | 7 Kas 2007 |
38İzleyin | CVE-2009-4035İstismar yok | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and vekde · kdegraphics · CWE-94 | Kritik9,3 | — | %3,8 | 21 Ara 2009 |
32İzleyin | CVE-2005-0064İstismar yok | Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary cxpdf · xpdf | Yüksek7,5 | — | %7,2 | 2 May 2005 |
32İzleyin | CVE-2007-4352İstismar yok | Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOfficxpdf · xpdf | Yüksek7,6 | — | %7,0 | 7 Kas 2007 |
32İzleyin | CVE-2005-3192İstismar yok | Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, axpdf · xpdf · CWE-119 | Yüksek7,5 | — | %6,1 | 7 Ara 2005 |
32İzleyin | CVE-2005-3627İstismar yok | Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to moxpdf · xpdf · CWE-119 | Yüksek7,5 | — | %5,5 | 31 Ara 2005 |
31İzleyin | CVE-2006-0301İstismar yok | Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framewxpdf · xpdf · CWE-119 | Yüksek7,5 | — | %4,5 | 30 Oca 2006 |
31İzleyin | CVE-2005-3628İstismar yok | Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, popplxpdf · xpdf | Yüksek7,5 | — | %4,3 | 31 Ara 2005 |
31İzleyin | CVE-2006-0746İstismar yok | Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependexpdf · xpdf | Yüksek7,5 | — | %3,0 | 8 Mar 2006 |
31İzleyin | CVE-2005-0206İstismar yok | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux dxpdf · xpdf | Yüksek7,5 | — | %3,0 | 27 Nis 2005 |
31İzleyin | CVE-2000-0727İstismar yok | xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbixpdf · xpdf | Yüksek7,6 | — | %2,6 | 20 Eki 2000 |
31İzleyin | CVE-2006-1244İstismar yok | Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) xpdf · xpdf | Yüksek7,6 | — | %2,2 | 15 Mar 2006 |
29İzleyin | CVE-2007-0104İstismar yok | The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and otherxpdf · xpdf · CWE-20 | Orta6,8 | — | %6,1 | 8 Oca 2007 |
28İzleyin | CVE-2002-1384İstismar yok | Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code xpdf · xpdf | Yüksek7,2 | — | %0,7 | 2 Oca 2003 |
28İzleyin | CVE-2000-0728İstismar yok | xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.xpdf · xpdf | Yüksek7,2 | — | %0,4 | 20 Eki 2000 |
21İzleyin | CVE-2005-3193İstismar yok | Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,xpdf · xpdf · CWE-119 | Orta5,1 | — | %4,1 | 6 Ara 2005 |
21İzleyin | CVE-2005-3191İstismar yok | Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT streamxpdf · xpdf · CWE-119 | Orta5,1 | — | %4,1 | 6 Ara 2005 |
21İzleyin | CVE-2005-3626İstismar yok | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Orta5,0 | — | %3,4 | 31 Ara 2005 |
21İzleyin | CVE-2005-3624İstismar yok | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others alllibextractor · libextractor · CWE-189 | Orta5,0 | — | %2,3 | 31 Ara 2005 |
- CVE-2004-088843Planlayın
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
KritikCVSS 10,0İstismar yokEPSS %10kde · koffice27 Oca 2005
- CVE-2003-043442Planlayın
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metach
YüksekCVSS 7,5Kavram kanıtıEPSS %41adobe · acrobat24 Tem 2003
- CVE-2004-088942Planlayın
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
KritikCVSS 10,0İstismar yokEPSS %6xpdf · xpdf27 Oca 2005
- CVE-2005-362541Planlayın
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
KritikCVSS 10,0İstismar yokEPSS %4libextractor · libextractor31 Ara 2005
- CVE-2004-112539İzleyin
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3
KritikCVSS 9,3İstismar yokEPSS %7xpdf · xpdf10 Oca 2005
- CVE-2007-539339İzleyin
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbit
KritikCVSS 9,3İstismar yokEPSS %6xpdf · xpdf7 Kas 2007
- CVE-2007-539239İzleyin
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a cr
KritikCVSS 9,3İstismar yokEPSS %6xpdf · xpdf7 Kas 2007
- CVE-2009-403538İzleyin
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve
KritikCVSS 9,3İstismar yokEPSS %4kde · kdegraphics21 Ara 2009
- CVE-2005-006432İzleyin
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary c
YüksekCVSS 7,5İstismar yokEPSS %7xpdf · xpdf2 May 2005
- CVE-2007-435232İzleyin
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffic
YüksekCVSS 7,6İstismar yokEPSS %7xpdf · xpdf7 Kas 2007
- CVE-2005-319232İzleyin
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, a
YüksekCVSS 7,5İstismar yokEPSS %6xpdf · xpdf7 Ara 2005
- CVE-2005-362732İzleyin
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to mo
YüksekCVSS 7,5İstismar yokEPSS %6xpdf · xpdf31 Ara 2005
- CVE-2006-030131İzleyin
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framew
YüksekCVSS 7,5İstismar yokEPSS %5xpdf · xpdf30 Oca 2006
- CVE-2005-362831İzleyin
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppl
YüksekCVSS 7,5İstismar yokEPSS %4xpdf · xpdf31 Ara 2005
- CVE-2006-074631İzleyin
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-depende
YüksekCVSS 7,5İstismar yokEPSS %3xpdf · xpdf8 Mar 2006
- CVE-2005-020631İzleyin
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux d
YüksekCVSS 7,5İstismar yokEPSS %3xpdf · xpdf27 Nis 2005
- CVE-2000-072731İzleyin
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbi
YüksekCVSS 7,6İstismar yokEPSS %3xpdf · xpdf20 Eki 2000
- CVE-2006-124431İzleyin
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c)
YüksekCVSS 7,6İstismar yokEPSS %2xpdf · xpdf15 Mar 2006
- CVE-2007-010429İzleyin
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other
OrtaCVSS 6,8İstismar yokEPSS %6xpdf · xpdf8 Oca 2007
- CVE-2002-138428İzleyin
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code
YüksekCVSS 7,2İstismar yokEPSS %1xpdf · xpdf2 Oca 2003
- CVE-2000-072828İzleyin
xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.
YüksekCVSS 7,2İstismar yokEPSS %0xpdf · xpdf20 Eki 2000
- CVE-2005-319321İzleyin
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,
OrtaCVSS 5,1İstismar yokEPSS %4xpdf · xpdf6 Ara 2005
- CVE-2005-319121İzleyin
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream
OrtaCVSS 5,1İstismar yokEPSS %4xpdf · xpdf6 Ara 2005
- CVE-2005-362621İzleyin
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
OrtaCVSS 5,0İstismar yokEPSS %3libextractor · libextractor31 Ara 2005
- CVE-2005-362421İzleyin
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others all
OrtaCVSS 5,0İstismar yokEPSS %2libextractor · libextractor31 Ara 2005