Skip to content
Noroxi

Xpdf records

26 published records for vendor xpdf.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
17
With a fix record
92.3%
Median publish → KEV
No record has entered KEV

All records

26 records
  • Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta

    CriticalCVSS 10.0No exploitEPSS 10%

    kde · kofficeJan 27, 2005

  • Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metach

    HighCVSS 7.5Proof of conceptEPSS 41%

    adobe · acrobatJul 24, 2003

  • Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv

    CriticalCVSS 10.0No exploitEPSS 6%

    xpdf · xpdfJan 27, 2005

  • Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial

    CriticalCVSS 10.0No exploitEPSS 4%

    libextractor · libextractorDec 31, 2005

  • CVE-2004-1125
    39Monitor

    Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3

    CriticalCVSS 9.3No exploitEPSS 7%

    xpdf · xpdfJan 10, 2005

  • CVE-2007-5393
    39Monitor

    Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbit

    CriticalCVSS 9.3No exploitEPSS 6%

    xpdf · xpdfNov 7, 2007

  • CVE-2007-5392
    39Monitor

    Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a cr

    CriticalCVSS 9.3No exploitEPSS 6%

    xpdf · xpdfNov 7, 2007

  • CVE-2009-4035
    38Monitor

    The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve

    CriticalCVSS 9.3No exploitEPSS 4%

    kde · kdegraphicsDec 21, 2009

  • CVE-2005-0064
    32Monitor

    Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary c

    HighCVSS 7.5No exploitEPSS 7%

    xpdf · xpdfMay 2, 2005

  • CVE-2007-4352
    32Monitor

    Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffic

    HighCVSS 7.6No exploitEPSS 7%

    xpdf · xpdfNov 7, 2007

  • CVE-2005-3192
    32Monitor

    Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, a

    HighCVSS 7.5No exploitEPSS 6%

    xpdf · xpdfDec 7, 2005

  • CVE-2005-3627
    32Monitor

    Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to mo

    HighCVSS 7.5No exploitEPSS 6%

    xpdf · xpdfDec 31, 2005

  • CVE-2006-0301
    31Monitor

    Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framew

    HighCVSS 7.5No exploitEPSS 5%

    xpdf · xpdfJan 30, 2006

  • CVE-2005-3628
    31Monitor

    Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppl

    HighCVSS 7.5No exploitEPSS 4%

    xpdf · xpdfDec 31, 2005

  • CVE-2006-0746
    31Monitor

    Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-depende

    HighCVSS 7.5No exploitEPSS 3%

    xpdf · xpdfMar 8, 2006

  • CVE-2005-0206
    31Monitor

    The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux d

    HighCVSS 7.5No exploitEPSS 3%

    xpdf · xpdfApr 27, 2005

  • CVE-2000-0727
    31Monitor

    xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbi

    HighCVSS 7.6No exploitEPSS 3%

    xpdf · xpdfOct 20, 2000

  • CVE-2006-1244
    31Monitor

    Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c)

    HighCVSS 7.6No exploitEPSS 2%

    xpdf · xpdfMar 15, 2006

  • CVE-2007-0104
    29Monitor

    The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other

    MediumCVSS 6.8No exploitEPSS 6%

    xpdf · xpdfJan 8, 2007

  • CVE-2002-1384
    28Monitor

    Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code

    HighCVSS 7.2No exploitEPSS 1%

    xpdf · xpdfJan 2, 2003

  • CVE-2000-0728
    28Monitor

    xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

    HighCVSS 7.2No exploitEPSS 0%

    xpdf · xpdfOct 20, 2000

  • CVE-2005-3193
    21Monitor

    Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,

    MediumCVSS 5.1No exploitEPSS 4%

    xpdf · xpdfDec 6, 2005

  • CVE-2005-3191
    21Monitor

    Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream

    MediumCVSS 5.1No exploitEPSS 4%

    xpdf · xpdfDec 6, 2005

  • CVE-2005-3626
    21Monitor

    Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial

    MediumCVSS 5.0No exploitEPSS 3%

    libextractor · libextractorDec 31, 2005

  • CVE-2005-3624
    21Monitor

    The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others all

    MediumCVSS 5.0No exploitEPSS 2%

    libextractor · libextractorDec 31, 2005