Xpdf records
26 published records for vendor xpdf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 17
- With a fix record
- 92.3%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-20 Improper Input Validation2
- CWE-399 Resource Management Errors2
- CWE-189 Numeric Errors1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2004-0888No exploit | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Critical10.0 | — | 9.5% | Jan 27, 2005 |
42Plan | CVE-2003-0434Proof of concept | Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metachadobe · acrobat | High7.5 | — | 40.9% | Jul 24, 2003 |
42Plan | CVE-2004-0889No exploit | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Critical10.0 | — | 6.2% | Jan 27, 2005 |
41Plan | CVE-2005-3625No exploit | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Critical10.0 | — | 3.8% | Dec 31, 2005 |
39Monitor | CVE-2004-1125No exploit | Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3xpdf · xpdf · CWE-20 | Critical9.3 | — | 6.6% | Jan 10, 2005 |
39Monitor | CVE-2007-5393No exploit | Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitxpdf · xpdf · CWE-119 | Critical9.3 | — | 6.4% | Nov 7, 2007 |
39Monitor | CVE-2007-5392No exploit | Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crxpdf · xpdf · CWE-119 | Critical9.3 | — | 6.4% | Nov 7, 2007 |
38Monitor | CVE-2009-4035No exploit | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and vekde · kdegraphics · CWE-94 | Critical9.3 | — | 3.8% | Dec 21, 2009 |
32Monitor | CVE-2005-0064No exploit | Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary cxpdf · xpdf | High7.5 | — | 7.2% | May 2, 2005 |
32Monitor | CVE-2007-4352No exploit | Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOfficxpdf · xpdf | High7.6 | — | 7.0% | Nov 7, 2007 |
32Monitor | CVE-2005-3192No exploit | Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, axpdf · xpdf · CWE-119 | High7.5 | — | 6.1% | Dec 7, 2005 |
32Monitor | CVE-2005-3627No exploit | Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to moxpdf · xpdf · CWE-119 | High7.5 | — | 5.5% | Dec 31, 2005 |
31Monitor | CVE-2006-0301No exploit | Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framewxpdf · xpdf · CWE-119 | High7.5 | — | 4.5% | Jan 30, 2006 |
31Monitor | CVE-2005-3628No exploit | Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, popplxpdf · xpdf | High7.5 | — | 4.3% | Dec 31, 2005 |
31Monitor | CVE-2006-0746No exploit | Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependexpdf · xpdf | High7.5 | — | 3.0% | Mar 8, 2006 |
31Monitor | CVE-2005-0206No exploit | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux dxpdf · xpdf | High7.5 | — | 3.0% | Apr 27, 2005 |
31Monitor | CVE-2000-0727No exploit | xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbixpdf · xpdf | High7.6 | — | 2.6% | Oct 20, 2000 |
31Monitor | CVE-2006-1244No exploit | Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) xpdf · xpdf | High7.6 | — | 2.2% | Mar 15, 2006 |
29Monitor | CVE-2007-0104No exploit | The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and otherxpdf · xpdf · CWE-20 | Medium6.8 | — | 6.1% | Jan 8, 2007 |
28Monitor | CVE-2002-1384No exploit | Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code xpdf · xpdf | High7.2 | — | 0.7% | Jan 2, 2003 |
28Monitor | CVE-2000-0728No exploit | xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.xpdf · xpdf | High7.2 | — | 0.4% | Oct 20, 2000 |
21Monitor | CVE-2005-3193No exploit | Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,xpdf · xpdf · CWE-119 | Medium5.1 | — | 4.1% | Dec 6, 2005 |
21Monitor | CVE-2005-3191No exploit | Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT streamxpdf · xpdf · CWE-119 | Medium5.1 | — | 4.1% | Dec 6, 2005 |
21Monitor | CVE-2005-3626No exploit | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Medium5.0 | — | 3.4% | Dec 31, 2005 |
21Monitor | CVE-2005-3624No exploit | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others alllibextractor · libextractor · CWE-189 | Medium5.0 | — | 2.3% | Dec 31, 2005 |
- CVE-2004-088843Plan
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
CriticalCVSS 10.0No exploitEPSS 10%kde · kofficeJan 27, 2005
- CVE-2003-043442Plan
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metach
HighCVSS 7.5Proof of conceptEPSS 41%adobe · acrobatJul 24, 2003
- CVE-2004-088942Plan
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
CriticalCVSS 10.0No exploitEPSS 6%xpdf · xpdfJan 27, 2005
- CVE-2005-362541Plan
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 4%libextractor · libextractorDec 31, 2005
- CVE-2004-112539Monitor
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3
CriticalCVSS 9.3No exploitEPSS 7%xpdf · xpdfJan 10, 2005
- CVE-2007-539339Monitor
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbit
CriticalCVSS 9.3No exploitEPSS 6%xpdf · xpdfNov 7, 2007
- CVE-2007-539239Monitor
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a cr
CriticalCVSS 9.3No exploitEPSS 6%xpdf · xpdfNov 7, 2007
- CVE-2009-403538Monitor
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve
CriticalCVSS 9.3No exploitEPSS 4%kde · kdegraphicsDec 21, 2009
- CVE-2005-006432Monitor
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary c
HighCVSS 7.5No exploitEPSS 7%xpdf · xpdfMay 2, 2005
- CVE-2007-435232Monitor
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffic
HighCVSS 7.6No exploitEPSS 7%xpdf · xpdfNov 7, 2007
- CVE-2005-319232Monitor
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, a
HighCVSS 7.5No exploitEPSS 6%xpdf · xpdfDec 7, 2005
- CVE-2005-362732Monitor
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to mo
HighCVSS 7.5No exploitEPSS 6%xpdf · xpdfDec 31, 2005
- CVE-2006-030131Monitor
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framew
HighCVSS 7.5No exploitEPSS 5%xpdf · xpdfJan 30, 2006
- CVE-2005-362831Monitor
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppl
HighCVSS 7.5No exploitEPSS 4%xpdf · xpdfDec 31, 2005
- CVE-2006-074631Monitor
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-depende
HighCVSS 7.5No exploitEPSS 3%xpdf · xpdfMar 8, 2006
- CVE-2005-020631Monitor
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux d
HighCVSS 7.5No exploitEPSS 3%xpdf · xpdfApr 27, 2005
- CVE-2000-072731Monitor
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbi
HighCVSS 7.6No exploitEPSS 3%xpdf · xpdfOct 20, 2000
- CVE-2006-124431Monitor
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c)
HighCVSS 7.6No exploitEPSS 2%xpdf · xpdfMar 15, 2006
- CVE-2007-010429Monitor
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other
MediumCVSS 6.8No exploitEPSS 6%xpdf · xpdfJan 8, 2007
- CVE-2002-138428Monitor
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code
HighCVSS 7.2No exploitEPSS 1%xpdf · xpdfJan 2, 2003
- CVE-2000-072828Monitor
xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.
HighCVSS 7.2No exploitEPSS 0%xpdf · xpdfOct 20, 2000
- CVE-2005-319321Monitor
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,
MediumCVSS 5.1No exploitEPSS 4%xpdf · xpdfDec 6, 2005
- CVE-2005-319121Monitor
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream
MediumCVSS 5.1No exploitEPSS 4%xpdf · xpdfDec 6, 2005
- CVE-2005-362621Monitor
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
MediumCVSS 5.0No exploitEPSS 3%libextractor · libextractorDec 31, 2005
- CVE-2005-362421Monitor
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others all
MediumCVSS 5.0No exploitEPSS 2%libextractor · libextractorDec 31, 2005