Записи foolabs
23 опубликованных записей вендора foolabs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 95,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-189 Numeric Errors8
- CWE-399 Resource Management Errors6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-20 Improper Input Validation3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2009-0165Эксплойта нет | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unsppoppler · poppler · CWE-189 | Критическая10,0 | — | 3,6 % | 23 апр. 2009 г. |
40В плане | CVE-2009-3608Эксплойта нет | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Критическая9,3 | — | 10,2 % | 21 окт. 2009 г. |
40В плане | CVE-2009-3604Эксплойта нет | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Критическая9,3 | — | 8,7 % | 21 окт. 2009 г. |
40В плане | CVE-2009-3606Эксплойта нет | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allowpoppler · poppler · CWE-189 | Критическая9,3 | — | 8,6 % | 21 окт. 2009 г. |
40В плане | CVE-2009-3603Эксплойта нет | Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackerpoppler · poppler · CWE-189 | Критическая9,3 | — | 8,6 % | 21 окт. 2009 г. |
32Наблюдать | CVE-2009-1182Эксплойта нет | Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other propoppler · poppler · CWE-119 | Высокая7,5 | — | 7,3 % | 23 апр. 2009 г. |
31Наблюдать | CVE-2011-0764Эксплойта нет | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereferenct1lib · t1lib · CWE-20 | Средняя6,8 | — | 13,1 % | 31 мар. 2011 г. |
29Наблюдать | CVE-2009-1179Эксплойта нет | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows poppler · poppler · CWE-189 | Средняя6,8 | — | 5,5 % | 23 апр. 2009 г. |
29Наблюдать | CVE-2009-0800Эксплойта нет | Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and otherpoppler · poppler · CWE-20 | Средняя6,8 | — | 5,5 % | 23 апр. 2009 г. |
29Наблюдать | CVE-2009-1180Эксплойта нет | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to poppler · poppler · CWE-399 | Средняя6,8 | — | 5,4 % | 23 апр. 2009 г. |
29Наблюдать | CVE-2009-0195Эксплойта нет | Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrarapple · cups · CWE-119 | Средняя6,8 | — | 5,4 % | 23 апр. 2009 г. |
28Наблюдать | CVE-2010-3704Эксплойта нет | The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up topoppler · poppler · CWE-20 | Средняя6,8 | — | 3,6 % | 5 нояб. 2010 г. |
27Наблюдать | CVE-2009-1144Эксплойта нет | Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpgentoo · gentoo linux · CWE-94 | Средняя6,9 | — | 0,4 % | 9 апр. 2009 г. |
20Наблюдать | CVE-2011-1552Эксплойта нет | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remotet1lib · t1lib · CWE-119 | Средняя4,3 | — | 10,4 % | 31 мар. 2011 г. |
19Наблюдать | CVE-2011-1554Эксплойта нет | Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a dt1lib · t1lib · CWE-189 | Средняя4,3 | — | 5,4 % | 31 мар. 2011 г. |
19Наблюдать | CVE-2011-1553Эксплойта нет | Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers t1lib · t1lib · CWE-399 | Средняя4,3 | — | 5,4 % | 31 мар. 2011 г. |
18Наблюдать | CVE-2009-3609Эксплойта нет | Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdpoppler · poppler · CWE-189 | Средняя4,3 | — | 4,7 % | 21 окт. 2009 г. |
18Наблюдать | CVE-2009-1181Эксплойта нет | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to poppler · poppler · CWE-399 | Средняя4,3 | — | 3,8 % | 23 апр. 2009 г. |
18Наблюдать | CVE-2009-1183Эксплойта нет | The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackerspoppler · poppler · CWE-399 | Средняя4,3 | — | 3,8 % | 23 апр. 2009 г. |
18Наблюдать | CVE-2009-0799Эксплойта нет | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to poppler · poppler · CWE-119 | Средняя4,3 | — | 3,8 % | 23 апр. 2009 г. |
18Наблюдать | CVE-2009-0146Эксплойта нет | Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackerfoolabs · xpdf · CWE-119 | Средняя4,3 | — | 2,8 % | 23 апр. 2009 г. |
18Наблюдать | CVE-2009-0147Эксплойта нет | Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackefoolabs · xpdf · CWE-189 | Средняя4,3 | — | 2,6 % | 23 апр. 2009 г. |
18Наблюдать | CVE-2009-0166Эксплойта нет | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of servifoolabs · xpdf · CWE-399 | Средняя4,3 | — | 2,3 % | 23 апр. 2009 г. |
- CVE-2009-016541В плане
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unsp
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %poppler · poppler23 апр. 2009 г.
- CVE-2009-360840В плане
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
КритическаяCVSS 9,3Эксплойта нетEPSS 10 %poppler · poppler21 окт. 2009 г.
- CVE-2009-360440В плане
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %kde · kpdf21 окт. 2009 г.
- CVE-2009-360640В плане
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %poppler · poppler21 окт. 2009 г.
- CVE-2009-360340В плане
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attacker
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %poppler · poppler21 окт. 2009 г.
- CVE-2009-118232Наблюдать
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other pro
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %poppler · poppler23 апр. 2009 г.
- CVE-2011-076431Наблюдать
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereferenc
СредняяCVSS 6,8Эксплойта нетEPSS 13 %t1lib · t1lib31 мар. 2011 г.
- CVE-2009-117929Наблюдать
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows
СредняяCVSS 6,8Эксплойта нетEPSS 6 %poppler · poppler23 апр. 2009 г.
- CVE-2009-080029Наблюдать
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other
СредняяCVSS 6,8Эксплойта нетEPSS 5 %poppler · poppler23 апр. 2009 г.
- CVE-2009-118029Наблюдать
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to
СредняяCVSS 6,8Эксплойта нетEPSS 5 %poppler · poppler23 апр. 2009 г.
- CVE-2009-019529Наблюдать
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrar
СредняяCVSS 6,8Эксплойта нетEPSS 5 %apple · cups23 апр. 2009 г.
- CVE-2010-370428Наблюдать
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to
СредняяCVSS 6,8Эксплойта нетEPSS 4 %poppler · poppler5 нояб. 2010 г.
- CVE-2009-114427Наблюдать
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xp
СредняяCVSS 6,9Эксплойта нетEPSS 0 %gentoo · gentoo linux9 апр. 2009 г.
- CVE-2011-155220Наблюдать
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote
СредняяCVSS 4,3Эксплойта нетEPSS 10 %t1lib · t1lib31 мар. 2011 г.
- CVE-2011-155419Наблюдать
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a d
СредняяCVSS 4,3Эксплойта нетEPSS 5 %t1lib · t1lib31 мар. 2011 г.
- CVE-2011-155319Наблюдать
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers
СредняяCVSS 4,3Эксплойта нетEPSS 5 %t1lib · t1lib31 мар. 2011 г.
- CVE-2009-360918Наблюдать
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kd
СредняяCVSS 4,3Эксплойта нетEPSS 5 %poppler · poppler21 окт. 2009 г.
- CVE-2009-118118Наблюдать
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to
СредняяCVSS 4,3Эксплойта нетEPSS 4 %poppler · poppler23 апр. 2009 г.
- CVE-2009-118318Наблюдать
The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers
СредняяCVSS 4,3Эксплойта нетEPSS 4 %poppler · poppler23 апр. 2009 г.
- CVE-2009-079918Наблюдать
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to
СредняяCVSS 4,3Эксплойта нетEPSS 4 %poppler · poppler23 апр. 2009 г.
- CVE-2009-014618Наблюдать
Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attacker
СредняяCVSS 4,3Эксплойта нетEPSS 3 %foolabs · xpdf23 апр. 2009 г.
- CVE-2009-014718Наблюдать
Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attacke
СредняяCVSS 4,3Эксплойта нетEPSS 3 %foolabs · xpdf23 апр. 2009 г.
- CVE-2009-016618Наблюдать
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of servi
СредняяCVSS 4,3Эксплойта нетEPSS 2 %foolabs · xpdf23 апр. 2009 г.