xpdfreader kayıtları
xpdfreader üreticisine ait 82 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,2
- Silahlaştırılmış
- 1 · %1,2
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %13,4
- Yayından KEV’e ortanca
- 71 gün
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write17
- CWE-125 Out-of-bounds Read14
- CWE-476 NULL Pointer Dereference12
- CWE-369 Divide By Zero10
- CWE-674 Uncontrolled Recursion8
- CWE-190 Integer Overflow or Wraparound5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
82 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
84Hemen | CVE-2021-30860Silahlaştırılmış | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | Yüksek7,8 | KEV | %76,0 | 24 Ağu 2021 |
32İzleyin | CVE-2012-2142İstismar yok | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapefreedesktop · poppler | Yüksek7,8 | — | %2,9 | 9 Oca 2020 |
31İzleyin | CVE-2010-3702İstismar yok | The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphicsapple · cups · CWE-476 | Yüksek7,5 | — | %2,8 | 5 Kas 2010 |
31İzleyin | CVE-2020-35376İstismar yok | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getxpdfreader · xpdf · CWE-787 | Yüksek7,5 | — | %2,1 | 26 Ara 2020 |
31İzleyin | CVE-2022-30524Kavram kanıtı | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters axpdfreader · xpdf · CWE-787 | Yüksek7,8 | — | %1,6 | 9 May 2022 |
31İzleyin | CVE-2018-11033İstismar yok | The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of servicexpdfreader · xpdf · CWE-119 | Yüksek7,8 | — | %1,3 | 13 May 2018 |
31İzleyin | CVE-2019-9878İstismar yok | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdpdfalto project · pdfalto · CWE-125 | Yüksek7,8 | — | %1,2 | 21 Mar 2019 |
31İzleyin | CVE-2022-33108İstismar yok | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.xpdfreader · xpdf · CWE-787 | Yüksek7,8 | — | %1,1 | 28 Haz 2022 |
31İzleyin | CVE-2019-9877İstismar yok | There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (forxpdfreader · xpdf · CWE-125 | Yüksek7,8 | — | %1,1 | 21 Mar 2019 |
31İzleyin | CVE-2020-24999İstismar yok | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.xpdfreader · xpdf · CWE-787 | Yüksek7,8 | — | %1,1 | 3 Eyl 2020 |
31İzleyin | CVE-2020-24996İstismar yok | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.xpdfreader · xpdf · CWE-665 | Yüksek7,8 | — | %1,1 | 3 Eyl 2020 |
31İzleyin | CVE-2018-8100İstismar yok | The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow axpdfreader · xpdf · CWE-787 | Yüksek7,8 | — | %0,9 | 13 Mar 2018 |
31İzleyin | CVE-2022-38222İstismar yok | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.xpdfreader · xpdf · CWE-416 | Yüksek7,8 | — | %0,5 | 28 Eyl 2022 |
31İzleyin | CVE-2022-38928İstismar yok | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.xpdfreader · xpdf · CWE-476 | Yüksek7,8 | — | %0,4 | 21 Eyl 2022 |
31İzleyin | CVE-2022-38171İstismar yok | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).xpdfreader · xpdf · CWE-190 | Yüksek7,8 | — | %0,3 | 22 Ağu 2022 |
30İzleyin | CVE-2007-3387İstismar yok | Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,apple · cups · CWE-190 | Orta6,8 | — | %8,6 | 30 Tem 2007 |
30İzleyin | CVE-2021-36493İstismar yok | Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.xpdfreader · xpdf · CWE-787 | Yüksek7,5 | — | %0,9 | 3 Şub 2023 |
22İzleyin | CVE-2018-16369İstismar yok | XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, relatedxpdfreader · xpdf | Orta5,5 | — | %1,6 | 2 Eyl 2018 |
22İzleyin | CVE-2018-18454İstismar yok | CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via axpdfreader · xpdf · CWE-125 | Orta5,5 | — | %1,2 | 18 Eki 2018 |
22İzleyin | CVE-2018-18459İstismar yok | The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) vxpdfreader · xpdf · CWE-476 | Orta5,5 | — | %1,1 | 18 Eki 2018 |
22İzleyin | CVE-2018-18458İstismar yok | The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereferencexpdfreader · xpdf · CWE-476 | Orta5,5 | — | %1,1 | 18 Eki 2018 |
22İzleyin | CVE-2018-18457İstismar yok | The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) vxpdfreader · xpdf · CWE-476 | Orta5,5 | — | %1,1 | 18 Eki 2018 |
22İzleyin | CVE-2018-18455İstismar yok | The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vixpdfreader · xpdf · CWE-125 | Orta5,5 | — | %1,1 | 18 Eki 2018 |
22İzleyin | CVE-2018-16368İstismar yok | SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer overxpdfreader · xpdf · CWE-125 | Orta5,5 | — | %1,1 | 2 Eyl 2018 |
22İzleyin | CVE-2019-10018İstismar yok | An issue was discovered in Xpdf 4.01.01.xpdfreader · xpdf · CWE-369 | Orta5,5 | — | %1,1 | 24 Mar 2019 |
- CVE-2021-3086084Hemen
An integer overflow was addressed with improved input validation.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %76apple · ipados24 Ağu 2021
- CVE-2012-214232İzleyin
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape
YüksekCVSS 7,8İstismar yokEPSS %3freedesktop · poppler9 Oca 2020
- CVE-2010-370231İzleyin
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics
YüksekCVSS 7,5İstismar yokEPSS %3apple · cups5 Kas 2010
- CVE-2020-3537631İzleyin
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::get
YüksekCVSS 7,5İstismar yokEPSS %2xpdfreader · xpdf26 Ara 2020
- CVE-2022-3052431İzleyin
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters a
YüksekCVSS 7,8Kavram kanıtıEPSS %2xpdfreader · xpdf9 May 2022
- CVE-2018-1103331İzleyin
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service
YüksekCVSS 7,8İstismar yokEPSS %1xpdfreader · xpdf13 May 2018
- CVE-2019-987831İzleyin
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pd
YüksekCVSS 7,8İstismar yokEPSS %1pdfalto project · pdfalto21 Mar 2019
- CVE-2022-3310831İzleyin
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
YüksekCVSS 7,8İstismar yokEPSS %1xpdfreader · xpdf28 Haz 2022
- CVE-2019-987731İzleyin
There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for
YüksekCVSS 7,8İstismar yokEPSS %1xpdfreader · xpdf21 Mar 2019
- CVE-2020-2499931İzleyin
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.
YüksekCVSS 7,8İstismar yokEPSS %1xpdfreader · xpdf3 Eyl 2020
- CVE-2020-2499631İzleyin
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.
YüksekCVSS 7,8İstismar yokEPSS %1xpdfreader · xpdf3 Eyl 2020
- CVE-2018-810031İzleyin
The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow a
YüksekCVSS 7,8İstismar yokEPSS %1xpdfreader · xpdf13 Mar 2018
- CVE-2022-3822231İzleyin
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.
YüksekCVSS 7,8İstismar yokEPSS %0xpdfreader · xpdf28 Eyl 2022
- CVE-2022-3892831İzleyin
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
YüksekCVSS 7,8İstismar yokEPSS %0xpdfreader · xpdf21 Eyl 2022
- CVE-2022-3817131İzleyin
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).
YüksekCVSS 7,8İstismar yokEPSS %0xpdfreader · xpdf22 Ağu 2022
- CVE-2007-338730İzleyin
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,
OrtaCVSS 6,8İstismar yokEPSS %9apple · cups30 Tem 2007
- CVE-2021-3649330İzleyin
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
YüksekCVSS 7,5İstismar yokEPSS %1xpdfreader · xpdf3 Şub 2023
- CVE-2018-1636922İzleyin
XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related
OrtaCVSS 5,5İstismar yokEPSS %2xpdfreader · xpdf2 Eyl 2018
- CVE-2018-1845422İzleyin
CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf18 Eki 2018
- CVE-2018-1845922İzleyin
The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf18 Eki 2018
- CVE-2018-1845822İzleyin
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf18 Eki 2018
- CVE-2018-1845722İzleyin
The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf18 Eki 2018
- CVE-2018-1845522İzleyin
The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf18 Eki 2018
- CVE-2018-1636822İzleyin
SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf2 Eyl 2018
- CVE-2019-1001822İzleyin
An issue was discovered in Xpdf 4.01.01.
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf24 Mar 2019