Записи Xpdf
26 опубликованных записей вендора xpdf.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 17
- С записью об исправлении
- 92,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-20 Improper Input Validation2
- CWE-399 Resource Management Errors2
- CWE-189 Numeric Errors1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2004-0888Эксплойта нет | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Критическая10,0 | — | 9,5 % | 27 янв. 2005 г. |
42В плане | CVE-2003-0434Proof of concept | Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metachadobe · acrobat | Высокая7,5 | — | 40,9 % | 24 июл. 2003 г. |
42В плане | CVE-2004-0889Эксплойта нет | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Критическая10,0 | — | 6,2 % | 27 янв. 2005 г. |
41В плане | CVE-2005-3625Эксплойта нет | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Критическая10,0 | — | 3,8 % | 31 дек. 2005 г. |
39Наблюдать | CVE-2004-1125Эксплойта нет | Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3xpdf · xpdf · CWE-20 | Критическая9,3 | — | 6,6 % | 10 янв. 2005 г. |
39Наблюдать | CVE-2007-5393Эксплойта нет | Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitxpdf · xpdf · CWE-119 | Критическая9,3 | — | 6,4 % | 7 нояб. 2007 г. |
39Наблюдать | CVE-2007-5392Эксплойта нет | Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crxpdf · xpdf · CWE-119 | Критическая9,3 | — | 6,4 % | 7 нояб. 2007 г. |
38Наблюдать | CVE-2009-4035Эксплойта нет | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and vekde · kdegraphics · CWE-94 | Критическая9,3 | — | 3,8 % | 21 дек. 2009 г. |
32Наблюдать | CVE-2005-0064Эксплойта нет | Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary cxpdf · xpdf | Высокая7,5 | — | 7,2 % | 2 мая 2005 г. |
32Наблюдать | CVE-2007-4352Эксплойта нет | Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOfficxpdf · xpdf | Высокая7,6 | — | 7,0 % | 7 нояб. 2007 г. |
32Наблюдать | CVE-2005-3192Эксплойта нет | Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, axpdf · xpdf · CWE-119 | Высокая7,5 | — | 6,1 % | 7 дек. 2005 г. |
32Наблюдать | CVE-2005-3627Эксплойта нет | Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to moxpdf · xpdf · CWE-119 | Высокая7,5 | — | 5,5 % | 31 дек. 2005 г. |
31Наблюдать | CVE-2006-0301Эксплойта нет | Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framewxpdf · xpdf · CWE-119 | Высокая7,5 | — | 4,5 % | 30 янв. 2006 г. |
31Наблюдать | CVE-2005-3628Эксплойта нет | Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, popplxpdf · xpdf | Высокая7,5 | — | 4,3 % | 31 дек. 2005 г. |
31Наблюдать | CVE-2006-0746Эксплойта нет | Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependexpdf · xpdf | Высокая7,5 | — | 3,0 % | 8 мар. 2006 г. |
31Наблюдать | CVE-2005-0206Эксплойта нет | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux dxpdf · xpdf | Высокая7,5 | — | 3,0 % | 27 апр. 2005 г. |
31Наблюдать | CVE-2000-0727Эксплойта нет | xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbixpdf · xpdf | Высокая7,6 | — | 2,6 % | 20 окт. 2000 г. |
31Наблюдать | CVE-2006-1244Эксплойта нет | Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) xpdf · xpdf | Высокая7,6 | — | 2,2 % | 15 мар. 2006 г. |
29Наблюдать | CVE-2007-0104Эксплойта нет | The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and otherxpdf · xpdf · CWE-20 | Средняя6,8 | — | 6,1 % | 8 янв. 2007 г. |
28Наблюдать | CVE-2002-1384Эксплойта нет | Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code xpdf · xpdf | Высокая7,2 | — | 0,7 % | 2 янв. 2003 г. |
28Наблюдать | CVE-2000-0728Эксплойта нет | xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.xpdf · xpdf | Высокая7,2 | — | 0,4 % | 20 окт. 2000 г. |
21Наблюдать | CVE-2005-3193Эксплойта нет | Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,xpdf · xpdf · CWE-119 | Средняя5,1 | — | 4,1 % | 6 дек. 2005 г. |
21Наблюдать | CVE-2005-3191Эксплойта нет | Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT streamxpdf · xpdf · CWE-119 | Средняя5,1 | — | 4,1 % | 6 дек. 2005 г. |
21Наблюдать | CVE-2005-3626Эксплойта нет | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Средняя5,0 | — | 3,4 % | 31 дек. 2005 г. |
21Наблюдать | CVE-2005-3624Эксплойта нет | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others alllibextractor · libextractor · CWE-189 | Средняя5,0 | — | 2,3 % | 31 дек. 2005 г. |
- CVE-2004-088843В плане
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %kde · koffice27 янв. 2005 г.
- CVE-2003-043442В плане
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metach
ВысокаяCVSS 7,5Proof of conceptEPSS 41 %adobe · acrobat24 июл. 2003 г.
- CVE-2004-088942В плане
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %xpdf · xpdf27 янв. 2005 г.
- CVE-2005-362541В плане
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %libextractor · libextractor31 дек. 2005 г.
- CVE-2004-112539Наблюдать
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %xpdf · xpdf10 янв. 2005 г.
- CVE-2007-539339Наблюдать
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbit
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %xpdf · xpdf7 нояб. 2007 г.
- CVE-2007-539239Наблюдать
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a cr
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %xpdf · xpdf7 нояб. 2007 г.
- CVE-2009-403538Наблюдать
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %kde · kdegraphics21 дек. 2009 г.
- CVE-2005-006432Наблюдать
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary c
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %xpdf · xpdf2 мая 2005 г.
- CVE-2007-435232Наблюдать
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffic
ВысокаяCVSS 7,6Эксплойта нетEPSS 7 %xpdf · xpdf7 нояб. 2007 г.
- CVE-2005-319232Наблюдать
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, a
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %xpdf · xpdf7 дек. 2005 г.
- CVE-2005-362732Наблюдать
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to mo
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %xpdf · xpdf31 дек. 2005 г.
- CVE-2006-030131Наблюдать
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framew
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %xpdf · xpdf30 янв. 2006 г.
- CVE-2005-362831Наблюдать
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppl
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %xpdf · xpdf31 дек. 2005 г.
- CVE-2006-074631Наблюдать
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-depende
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %xpdf · xpdf8 мар. 2006 г.
- CVE-2005-020631Наблюдать
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux d
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %xpdf · xpdf27 апр. 2005 г.
- CVE-2000-072731Наблюдать
xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbi
ВысокаяCVSS 7,6Эксплойта нетEPSS 3 %xpdf · xpdf20 окт. 2000 г.
- CVE-2006-124431Наблюдать
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c)
ВысокаяCVSS 7,6Эксплойта нетEPSS 2 %xpdf · xpdf15 мар. 2006 г.
- CVE-2007-010429Наблюдать
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other
СредняяCVSS 6,8Эксплойта нетEPSS 6 %xpdf · xpdf8 янв. 2007 г.
- CVE-2002-138428Наблюдать
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %xpdf · xpdf2 янв. 2003 г.
- CVE-2000-072828Наблюдать
xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %xpdf · xpdf20 окт. 2000 г.
- CVE-2005-319321Наблюдать
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier,
СредняяCVSS 5,1Эксплойта нетEPSS 4 %xpdf · xpdf6 дек. 2005 г.
- CVE-2005-319121Наблюдать
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream
СредняяCVSS 5,1Эксплойта нетEPSS 4 %xpdf · xpdf6 дек. 2005 г.
- CVE-2005-362621Наблюдать
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
СредняяCVSS 5,0Эксплойта нетEPSS 3 %libextractor · libextractor31 дек. 2005 г.
- CVE-2005-362421Наблюдать
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others all
СредняяCVSS 5,0Эксплойта нетEPSS 2 %libextractor · libextractor31 дек. 2005 г.