Skip to content
Noroxi

Freedesktop records

150 published records for vendor freedesktop.

Researcher profile

Entered KEV
1 · 0.7%
Weaponized
1 · 0.7%
Pre-auth RCE
6
With a fix record
90.7%
Median publish → KEV
71 days

All records

150 records
  • An integer overflow was addressed with improved input validation.

    HighCVSS 7.8KEVWeaponizedEPSS 76%

    apple · ipadosAug 24, 2021

  • Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

    CriticalCVSS 9.8No exploitEPSS 4%

    freedesktop · popplerMar 8, 2019

  • Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whi

    CriticalCVSS 9.8No exploitEPSS 3%

    fedoraproject · fedoraJan 13, 2017

  • A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause

    CriticalCVSS 9.8No exploitEPSS 2%

    freedesktop · gst-plugins-badJan 26, 2021

  • In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr

    CriticalCVSS 9.8No exploitEPSS 1%

    freedesktop · libinputJun 4, 2026

  • nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

    CriticalCVSS 9.1No exploitEPSS 3%

    freedesktop · libbsdJan 8, 2020

  • CVE-2017-2820
    36Monitor

    An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.

    HighCVSS 8.8No exploitEPSS 4%

    freedesktop · popplerJul 12, 2017

  • CVE-2019-9200
    36Monitor

    A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered b

    HighCVSS 8.8No exploitEPSS 3%

    freedesktop · popplerFeb 26, 2019

  • CVE-2019-9543
    36Monitor

    An issue was discovered in Poppler 0.74.0.

    HighCVSS 8.8No exploitEPSS 3%

    freedesktop · popplerMar 1, 2019

  • CVE-2015-1877
    36Monitor

    The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables,

    HighCVSS 8.8No exploitEPSS 3%

    debian · debian linuxJun 2, 2021

  • CVE-2017-2814
    36Monitor

    An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.

    HighCVSS 8.8No exploitEPSS 3%

    freedesktop · popplerJul 12, 2017

  • An issue was discovered in Poppler 0.74.0.

    HighCVSS 8.8No exploitEPSS 3%

    freedesktop · popplerApr 5, 2019

  • The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWS

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · xdg-utilsMay 10, 2018

  • In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · popplerMay 23, 2019

  • In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF docume

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · popplerOct 17, 2017

  • CVE-2017-2818
    36Monitor

    An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · popplerJul 12, 2017

  • freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · popplerJan 2, 2018

  • Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · popplerSep 5, 2019

  • CVE-2019-9545
    36Monitor

    An issue was discovered in Poppler 0.74.0.

    HighCVSS 8.8No exploitEPSS 2%

    freedesktop · popplerMar 1, 2019

  • An issue was discovered in GStreamer gst-plugins-good before 1.28.2.

    CriticalCVSS 9.1No exploitEPSS 0%

    freedesktop · gst-plugins-goodMay 14, 2026

  • Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins

    HighCVSS 8.8No exploitEPSS 0%

    freedesktop · libinputApr 1, 2026

  • CVE-2013-4473
    32Monitor

    Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a

    HighCVSS 7.5No exploitEPSS 7%

    freedesktop · popplerNov 23, 2013

  • CVE-2015-8868
    32Monitor

    Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to caus

    HighCVSS 7.8No exploitEPSS 5%

    fedoraproject · fedoraMay 6, 2016

  • CVE-2012-2142
    32Monitor

    The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape

    HighCVSS 7.8No exploitEPSS 3%

    freedesktop · popplerJan 9, 2020

  • CVE-2019-7310
    32Monitor

    In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remot

    HighCVSS 7.8No exploitEPSS 2%

    freedesktop · popplerFeb 2, 2019