xpdfreader records
82 published records for vendor xpdfreader.
Researcher profile
- Entered KEV
- 1 · 1.2%
- Weaponized
- 1 · 1.2%
- Pre-auth RCE
- 1
- With a fix record
- 13.4%
- Median publish → KEV
- 71 days
Recurring classes
- CWE-787 Out-of-bounds Write17
- CWE-125 Out-of-bounds Read14
- CWE-476 NULL Pointer Dereference12
- CWE-369 Divide By Zero10
- CWE-674 Uncontrolled Recursion8
- CWE-190 Integer Overflow or Wraparound5
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
82 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
84Now | CVE-2021-30860Weaponized | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | High7.8 | KEV | 76.0% | Aug 24, 2021 |
32Monitor | CVE-2012-2142No exploit | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapefreedesktop · poppler | High7.8 | — | 2.9% | Jan 9, 2020 |
31Monitor | CVE-2010-3702No exploit | The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphicsapple · cups · CWE-476 | High7.5 | — | 2.8% | Nov 5, 2010 |
31Monitor | CVE-2020-35376No exploit | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getxpdfreader · xpdf · CWE-787 | High7.5 | — | 2.1% | Dec 26, 2020 |
31Monitor | CVE-2022-30524Proof of concept | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters axpdfreader · xpdf · CWE-787 | High7.8 | — | 1.6% | May 9, 2022 |
31Monitor | CVE-2018-11033No exploit | The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of servicexpdfreader · xpdf · CWE-119 | High7.8 | — | 1.3% | May 13, 2018 |
31Monitor | CVE-2019-9878No exploit | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdpdfalto project · pdfalto · CWE-125 | High7.8 | — | 1.2% | Mar 21, 2019 |
31Monitor | CVE-2022-33108No exploit | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.xpdfreader · xpdf · CWE-787 | High7.8 | — | 1.1% | Jun 28, 2022 |
31Monitor | CVE-2019-9877No exploit | There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (forxpdfreader · xpdf · CWE-125 | High7.8 | — | 1.1% | Mar 21, 2019 |
31Monitor | CVE-2020-24999No exploit | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.xpdfreader · xpdf · CWE-787 | High7.8 | — | 1.1% | Sep 3, 2020 |
31Monitor | CVE-2020-24996No exploit | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.xpdfreader · xpdf · CWE-665 | High7.8 | — | 1.1% | Sep 3, 2020 |
31Monitor | CVE-2018-8100No exploit | The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow axpdfreader · xpdf · CWE-787 | High7.8 | — | 0.9% | Mar 13, 2018 |
31Monitor | CVE-2022-38222No exploit | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.xpdfreader · xpdf · CWE-416 | High7.8 | — | 0.5% | Sep 28, 2022 |
31Monitor | CVE-2022-38928No exploit | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.xpdfreader · xpdf · CWE-476 | High7.8 | — | 0.4% | Sep 21, 2022 |
31Monitor | CVE-2022-38171No exploit | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).xpdfreader · xpdf · CWE-190 | High7.8 | — | 0.3% | Aug 22, 2022 |
30Monitor | CVE-2007-3387No exploit | Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,apple · cups · CWE-190 | Medium6.8 | — | 8.6% | Jul 30, 2007 |
30Monitor | CVE-2021-36493No exploit | Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.xpdfreader · xpdf · CWE-787 | High7.5 | — | 0.9% | Feb 3, 2023 |
22Monitor | CVE-2018-16369No exploit | XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, relatedxpdfreader · xpdf | Medium5.5 | — | 1.6% | Sep 2, 2018 |
22Monitor | CVE-2018-18454No exploit | CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via axpdfreader · xpdf · CWE-125 | Medium5.5 | — | 1.2% | Oct 18, 2018 |
22Monitor | CVE-2018-18459No exploit | The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) vxpdfreader · xpdf · CWE-476 | Medium5.5 | — | 1.1% | Oct 18, 2018 |
22Monitor | CVE-2018-18458No exploit | The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereferencexpdfreader · xpdf · CWE-476 | Medium5.5 | — | 1.1% | Oct 18, 2018 |
22Monitor | CVE-2018-18457No exploit | The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) vxpdfreader · xpdf · CWE-476 | Medium5.5 | — | 1.1% | Oct 18, 2018 |
22Monitor | CVE-2018-18455No exploit | The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vixpdfreader · xpdf · CWE-125 | Medium5.5 | — | 1.1% | Oct 18, 2018 |
22Monitor | CVE-2018-16368No exploit | SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer overxpdfreader · xpdf · CWE-125 | Medium5.5 | — | 1.1% | Sep 2, 2018 |
22Monitor | CVE-2019-10018No exploit | An issue was discovered in Xpdf 4.01.01.xpdfreader · xpdf · CWE-369 | Medium5.5 | — | 1.1% | Mar 24, 2019 |
- CVE-2021-3086084Now
An integer overflow was addressed with improved input validation.
HighCVSS 7.8KEVWeaponizedEPSS 76%apple · ipadosAug 24, 2021
- CVE-2012-214232Monitor
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape
HighCVSS 7.8No exploitEPSS 3%freedesktop · popplerJan 9, 2020
- CVE-2010-370231Monitor
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics
HighCVSS 7.5No exploitEPSS 3%apple · cupsNov 5, 2010
- CVE-2020-3537631Monitor
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::get
HighCVSS 7.5No exploitEPSS 2%xpdfreader · xpdfDec 26, 2020
- CVE-2022-3052431Monitor
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters a
HighCVSS 7.8Proof of conceptEPSS 2%xpdfreader · xpdfMay 9, 2022
- CVE-2018-1103331Monitor
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service
HighCVSS 7.8No exploitEPSS 1%xpdfreader · xpdfMay 13, 2018
- CVE-2019-987831Monitor
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pd
HighCVSS 7.8No exploitEPSS 1%pdfalto project · pdfaltoMar 21, 2019
- CVE-2022-3310831Monitor
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
HighCVSS 7.8No exploitEPSS 1%xpdfreader · xpdfJun 28, 2022
- CVE-2019-987731Monitor
There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for
HighCVSS 7.8No exploitEPSS 1%xpdfreader · xpdfMar 21, 2019
- CVE-2020-2499931Monitor
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.
HighCVSS 7.8No exploitEPSS 1%xpdfreader · xpdfSep 3, 2020
- CVE-2020-2499631Monitor
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.
HighCVSS 7.8No exploitEPSS 1%xpdfreader · xpdfSep 3, 2020
- CVE-2018-810031Monitor
The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow a
HighCVSS 7.8No exploitEPSS 1%xpdfreader · xpdfMar 13, 2018
- CVE-2022-3822231Monitor
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.
HighCVSS 7.8No exploitEPSS 0%xpdfreader · xpdfSep 28, 2022
- CVE-2022-3892831Monitor
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
HighCVSS 7.8No exploitEPSS 0%xpdfreader · xpdfSep 21, 2022
- CVE-2022-3817131Monitor
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).
HighCVSS 7.8No exploitEPSS 0%xpdfreader · xpdfAug 22, 2022
- CVE-2007-338730Monitor
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,
MediumCVSS 6.8No exploitEPSS 9%apple · cupsJul 30, 2007
- CVE-2021-3649330Monitor
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
HighCVSS 7.5No exploitEPSS 1%xpdfreader · xpdfFeb 3, 2023
- CVE-2018-1636922Monitor
XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related
MediumCVSS 5.5No exploitEPSS 2%xpdfreader · xpdfSep 2, 2018
- CVE-2018-1845422Monitor
CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfOct 18, 2018
- CVE-2018-1845922Monitor
The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfOct 18, 2018
- CVE-2018-1845822Monitor
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfOct 18, 2018
- CVE-2018-1845722Monitor
The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfOct 18, 2018
- CVE-2018-1845522Monitor
The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfOct 18, 2018
- CVE-2018-1636822Monitor
SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfSep 2, 2018
- CVE-2019-1001822Monitor
An issue was discovered in Xpdf 4.01.01.
MediumCVSS 5.5No exploitEPSS 1%xpdfreader · xpdfMar 24, 2019