Skip to content
Noroxi

xpdfreader records

82 published records for vendor xpdfreader.

Researcher profile

Entered KEV
1 · 1.2%
Weaponized
1 · 1.2%
Pre-auth RCE
1
With a fix record
13.4%
Median publish → KEV
71 days

All records

82 records
  • An integer overflow was addressed with improved input validation.

    HighCVSS 7.8KEVWeaponizedEPSS 76%

    apple · ipadosAug 24, 2021

  • CVE-2012-2142
    32Monitor

    The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape

    HighCVSS 7.8No exploitEPSS 3%

    freedesktop · popplerJan 9, 2020

  • CVE-2010-3702
    31Monitor

    The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics

    HighCVSS 7.5No exploitEPSS 3%

    apple · cupsNov 5, 2010

  • Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::get

    HighCVSS 7.5No exploitEPSS 2%

    xpdfreader · xpdfDec 26, 2020

  • There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters a

    HighCVSS 7.8Proof of conceptEPSS 2%

    xpdfreader · xpdfMay 9, 2022

  • The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service

    HighCVSS 7.8No exploitEPSS 1%

    xpdfreader · xpdfMay 13, 2018

  • CVE-2019-9878
    31Monitor

    There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pd

    HighCVSS 7.8No exploitEPSS 1%

    pdfalto project · pdfaltoMar 21, 2019

  • XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.

    HighCVSS 7.8No exploitEPSS 1%

    xpdfreader · xpdfJun 28, 2022

  • CVE-2019-9877
    31Monitor

    There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for

    HighCVSS 7.8No exploitEPSS 1%

    xpdfreader · xpdfMar 21, 2019

  • There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.

    HighCVSS 7.8No exploitEPSS 1%

    xpdfreader · xpdfSep 3, 2020

  • There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.

    HighCVSS 7.8No exploitEPSS 1%

    xpdfreader · xpdfSep 3, 2020

  • CVE-2018-8100
    31Monitor

    The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow a

    HighCVSS 7.8No exploitEPSS 1%

    xpdfreader · xpdfMar 13, 2018

  • There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.

    HighCVSS 7.8No exploitEPSS 0%

    xpdfreader · xpdfSep 28, 2022

  • XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

    HighCVSS 7.8No exploitEPSS 0%

    xpdfreader · xpdfSep 21, 2022

  • Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).

    HighCVSS 7.8No exploitEPSS 0%

    xpdfreader · xpdfAug 22, 2022

  • CVE-2007-3387
    30Monitor

    Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,

    MediumCVSS 6.8No exploitEPSS 9%

    apple · cupsJul 30, 2007

  • Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.

    HighCVSS 7.5No exploitEPSS 1%

    xpdfreader · xpdfFeb 3, 2023

  • XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related

    MediumCVSS 5.5No exploitEPSS 2%

    xpdfreader · xpdfSep 2, 2018

  • CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfOct 18, 2018

  • The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfOct 18, 2018

  • The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfOct 18, 2018

  • The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfOct 18, 2018

  • The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfOct 18, 2018

  • SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfSep 2, 2018

  • An issue was discovered in Xpdf 4.01.01.

    MediumCVSS 5.5No exploitEPSS 1%

    xpdfreader · xpdfMar 24, 2019