foolabs records
23 published records for vendor foolabs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 95.7%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-189 Numeric Errors8
- CWE-399 Resource Management Errors6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-20 Improper Input Validation3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2009-0165No exploit | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unsppoppler · poppler · CWE-189 | Critical10.0 | — | 3.6% | Apr 23, 2009 |
40Plan | CVE-2009-3608No exploit | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Critical9.3 | — | 10.2% | Oct 21, 2009 |
40Plan | CVE-2009-3604No exploit | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Critical9.3 | — | 8.7% | Oct 21, 2009 |
40Plan | CVE-2009-3606No exploit | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allowpoppler · poppler · CWE-189 | Critical9.3 | — | 8.6% | Oct 21, 2009 |
40Plan | CVE-2009-3603No exploit | Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackerpoppler · poppler · CWE-189 | Critical9.3 | — | 8.6% | Oct 21, 2009 |
32Monitor | CVE-2009-1182No exploit | Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other propoppler · poppler · CWE-119 | High7.5 | — | 7.3% | Apr 23, 2009 |
31Monitor | CVE-2011-0764No exploit | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereferenct1lib · t1lib · CWE-20 | Medium6.8 | — | 13.1% | Mar 31, 2011 |
29Monitor | CVE-2009-1179No exploit | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows poppler · poppler · CWE-189 | Medium6.8 | — | 5.5% | Apr 23, 2009 |
29Monitor | CVE-2009-0800No exploit | Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and otherpoppler · poppler · CWE-20 | Medium6.8 | — | 5.5% | Apr 23, 2009 |
29Monitor | CVE-2009-1180No exploit | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to poppler · poppler · CWE-399 | Medium6.8 | — | 5.4% | Apr 23, 2009 |
29Monitor | CVE-2009-0195No exploit | Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrarapple · cups · CWE-119 | Medium6.8 | — | 5.4% | Apr 23, 2009 |
28Monitor | CVE-2010-3704No exploit | The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up topoppler · poppler · CWE-20 | Medium6.8 | — | 3.6% | Nov 5, 2010 |
27Monitor | CVE-2009-1144No exploit | Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpgentoo · gentoo linux · CWE-94 | Medium6.9 | — | 0.4% | Apr 9, 2009 |
20Monitor | CVE-2011-1552No exploit | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remotet1lib · t1lib · CWE-119 | Medium4.3 | — | 10.4% | Mar 31, 2011 |
19Monitor | CVE-2011-1554No exploit | Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a dt1lib · t1lib · CWE-189 | Medium4.3 | — | 5.4% | Mar 31, 2011 |
19Monitor | CVE-2011-1553No exploit | Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers t1lib · t1lib · CWE-399 | Medium4.3 | — | 5.4% | Mar 31, 2011 |
18Monitor | CVE-2009-3609No exploit | Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdpoppler · poppler · CWE-189 | Medium4.3 | — | 4.7% | Oct 21, 2009 |
18Monitor | CVE-2009-1181No exploit | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to poppler · poppler · CWE-399 | Medium4.3 | — | 3.8% | Apr 23, 2009 |
18Monitor | CVE-2009-1183No exploit | The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackerspoppler · poppler · CWE-399 | Medium4.3 | — | 3.8% | Apr 23, 2009 |
18Monitor | CVE-2009-0799No exploit | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to poppler · poppler · CWE-119 | Medium4.3 | — | 3.8% | Apr 23, 2009 |
18Monitor | CVE-2009-0146No exploit | Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackerfoolabs · xpdf · CWE-119 | Medium4.3 | — | 2.8% | Apr 23, 2009 |
18Monitor | CVE-2009-0147No exploit | Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackefoolabs · xpdf · CWE-189 | Medium4.3 | — | 2.6% | Apr 23, 2009 |
18Monitor | CVE-2009-0166No exploit | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of servifoolabs · xpdf · CWE-399 | Medium4.3 | — | 2.3% | Apr 23, 2009 |
- CVE-2009-016541Plan
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unsp
CriticalCVSS 10.0No exploitEPSS 4%poppler · popplerApr 23, 2009
- CVE-2009-360840Plan
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
CriticalCVSS 9.3No exploitEPSS 10%poppler · popplerOct 21, 2009
- CVE-2009-360440Plan
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
CriticalCVSS 9.3No exploitEPSS 9%kde · kpdfOct 21, 2009
- CVE-2009-360640Plan
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow
CriticalCVSS 9.3No exploitEPSS 9%poppler · popplerOct 21, 2009
- CVE-2009-360340Plan
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attacker
CriticalCVSS 9.3No exploitEPSS 9%poppler · popplerOct 21, 2009
- CVE-2009-118232Monitor
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other pro
HighCVSS 7.5No exploitEPSS 7%poppler · popplerApr 23, 2009
- CVE-2011-076431Monitor
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereferenc
MediumCVSS 6.8No exploitEPSS 13%t1lib · t1libMar 31, 2011
- CVE-2009-117929Monitor
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows
MediumCVSS 6.8No exploitEPSS 6%poppler · popplerApr 23, 2009
- CVE-2009-080029Monitor
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other
MediumCVSS 6.8No exploitEPSS 5%poppler · popplerApr 23, 2009
- CVE-2009-118029Monitor
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to
MediumCVSS 6.8No exploitEPSS 5%poppler · popplerApr 23, 2009
- CVE-2009-019529Monitor
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrar
MediumCVSS 6.8No exploitEPSS 5%apple · cupsApr 23, 2009
- CVE-2010-370428Monitor
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to
MediumCVSS 6.8No exploitEPSS 4%poppler · popplerNov 5, 2010
- CVE-2009-114427Monitor
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xp
MediumCVSS 6.9No exploitEPSS 0%gentoo · gentoo linuxApr 9, 2009
- CVE-2011-155220Monitor
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote
MediumCVSS 4.3No exploitEPSS 10%t1lib · t1libMar 31, 2011
- CVE-2011-155419Monitor
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a d
MediumCVSS 4.3No exploitEPSS 5%t1lib · t1libMar 31, 2011
- CVE-2011-155319Monitor
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers
MediumCVSS 4.3No exploitEPSS 5%t1lib · t1libMar 31, 2011
- CVE-2009-360918Monitor
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kd
MediumCVSS 4.3No exploitEPSS 5%poppler · popplerOct 21, 2009
- CVE-2009-118118Monitor
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to
MediumCVSS 4.3No exploitEPSS 4%poppler · popplerApr 23, 2009
- CVE-2009-118318Monitor
The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers
MediumCVSS 4.3No exploitEPSS 4%poppler · popplerApr 23, 2009
- CVE-2009-079918Monitor
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to
MediumCVSS 4.3No exploitEPSS 4%poppler · popplerApr 23, 2009
- CVE-2009-014618Monitor
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attacker
MediumCVSS 4.3No exploitEPSS 3%foolabs · xpdfApr 23, 2009
- CVE-2009-014718Monitor
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attacke
MediumCVSS 4.3No exploitEPSS 3%foolabs · xpdfApr 23, 2009
- CVE-2009-016618Monitor
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of servi
MediumCVSS 4.3No exploitEPSS 2%foolabs · xpdfApr 23, 2009