Записи xpdfreader
82 опубликованных записей вендора xpdfreader.
Профиль для исследователя
- Попали в KEV
- 1 · 1,2 %
- С эксплойтом
- 1 · 1,2 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 13,4 %
- Медиана: публикация → KEV
- 71 дн.
Повторяющиеся классы
- CWE-787 Out-of-bounds Write17
- CWE-125 Out-of-bounds Read14
- CWE-476 NULL Pointer Dereference12
- CWE-369 Divide By Zero10
- CWE-674 Uncontrolled Recursion8
- CWE-190 Integer Overflow or Wraparound5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
82 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
84Срочно | CVE-2021-30860Готовый эксплойт | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | Высокая7,8 | KEV | 76,0 % | 24 авг. 2021 г. |
32Наблюдать | CVE-2012-2142Эксплойта нет | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapefreedesktop · poppler | Высокая7,8 | — | 2,9 % | 9 янв. 2020 г. |
31Наблюдать | CVE-2010-3702Эксплойта нет | The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphicsapple · cups · CWE-476 | Высокая7,5 | — | 2,8 % | 5 нояб. 2010 г. |
31Наблюдать | CVE-2020-35376Эксплойта нет | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getxpdfreader · xpdf · CWE-787 | Высокая7,5 | — | 2,1 % | 26 дек. 2020 г. |
31Наблюдать | CVE-2022-30524Proof of concept | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters axpdfreader · xpdf · CWE-787 | Высокая7,8 | — | 1,6 % | 9 мая 2022 г. |
31Наблюдать | CVE-2018-11033Эксплойта нет | The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of servicexpdfreader · xpdf · CWE-119 | Высокая7,8 | — | 1,3 % | 13 мая 2018 г. |
31Наблюдать | CVE-2019-9878Эксплойта нет | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdpdfalto project · pdfalto · CWE-125 | Высокая7,8 | — | 1,2 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2022-33108Эксплойта нет | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.xpdfreader · xpdf · CWE-787 | Высокая7,8 | — | 1,1 % | 28 июн. 2022 г. |
31Наблюдать | CVE-2019-9877Эксплойта нет | There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (forxpdfreader · xpdf · CWE-125 | Высокая7,8 | — | 1,1 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2020-24999Эксплойта нет | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.xpdfreader · xpdf · CWE-787 | Высокая7,8 | — | 1,1 % | 3 сент. 2020 г. |
31Наблюдать | CVE-2020-24996Эксплойта нет | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.xpdfreader · xpdf · CWE-665 | Высокая7,8 | — | 1,1 % | 3 сент. 2020 г. |
31Наблюдать | CVE-2018-8100Эксплойта нет | The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow axpdfreader · xpdf · CWE-787 | Высокая7,8 | — | 0,9 % | 13 мар. 2018 г. |
31Наблюдать | CVE-2022-38222Эксплойта нет | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.xpdfreader · xpdf · CWE-416 | Высокая7,8 | — | 0,5 % | 28 сент. 2022 г. |
31Наблюдать | CVE-2022-38928Эксплойта нет | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.xpdfreader · xpdf · CWE-476 | Высокая7,8 | — | 0,4 % | 21 сент. 2022 г. |
31Наблюдать | CVE-2022-38171Эксплойта нет | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).xpdfreader · xpdf · CWE-190 | Высокая7,8 | — | 0,3 % | 22 авг. 2022 г. |
30Наблюдать | CVE-2007-3387Эксплойта нет | Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,apple · cups · CWE-190 | Средняя6,8 | — | 8,6 % | 30 июл. 2007 г. |
30Наблюдать | CVE-2021-36493Эксплойта нет | Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.xpdfreader · xpdf · CWE-787 | Высокая7,5 | — | 0,9 % | 3 февр. 2023 г. |
22Наблюдать | CVE-2018-16369Эксплойта нет | XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, relatedxpdfreader · xpdf | Средняя5,5 | — | 1,6 % | 2 сент. 2018 г. |
22Наблюдать | CVE-2018-18454Эксплойта нет | CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via axpdfreader · xpdf · CWE-125 | Средняя5,5 | — | 1,2 % | 18 окт. 2018 г. |
22Наблюдать | CVE-2018-18459Эксплойта нет | The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) vxpdfreader · xpdf · CWE-476 | Средняя5,5 | — | 1,1 % | 18 окт. 2018 г. |
22Наблюдать | CVE-2018-18458Эксплойта нет | The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereferencexpdfreader · xpdf · CWE-476 | Средняя5,5 | — | 1,1 % | 18 окт. 2018 г. |
22Наблюдать | CVE-2018-18457Эксплойта нет | The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) vxpdfreader · xpdf · CWE-476 | Средняя5,5 | — | 1,1 % | 18 окт. 2018 г. |
22Наблюдать | CVE-2018-18455Эксплойта нет | The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vixpdfreader · xpdf · CWE-125 | Средняя5,5 | — | 1,1 % | 18 окт. 2018 г. |
22Наблюдать | CVE-2018-16368Эксплойта нет | SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer overxpdfreader · xpdf · CWE-125 | Средняя5,5 | — | 1,1 % | 2 сент. 2018 г. |
22Наблюдать | CVE-2019-10018Эксплойта нет | An issue was discovered in Xpdf 4.01.01.xpdfreader · xpdf · CWE-369 | Средняя5,5 | — | 1,1 % | 24 мар. 2019 г. |
- CVE-2021-3086084Срочно
An integer overflow was addressed with improved input validation.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 76 %apple · ipados24 авг. 2021 г.
- CVE-2012-214232Наблюдать
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %freedesktop · poppler9 янв. 2020 г.
- CVE-2010-370231Наблюдать
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %apple · cups5 нояб. 2010 г.
- CVE-2020-3537631Наблюдать
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::get
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %xpdfreader · xpdf26 дек. 2020 г.
- CVE-2022-3052431Наблюдать
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters a
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %xpdfreader · xpdf9 мая 2022 г.
- CVE-2018-1103331Наблюдать
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xpdfreader · xpdf13 мая 2018 г.
- CVE-2019-987831Наблюдать
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pd
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %pdfalto project · pdfalto21 мар. 2019 г.
- CVE-2022-3310831Наблюдать
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xpdfreader · xpdf28 июн. 2022 г.
- CVE-2019-987731Наблюдать
There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xpdfreader · xpdf21 мар. 2019 г.
- CVE-2020-2499931Наблюдать
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xpdfreader · xpdf3 сент. 2020 г.
- CVE-2020-2499631Наблюдать
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xpdfreader · xpdf3 сент. 2020 г.
- CVE-2018-810031Наблюдать
The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow a
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %xpdfreader · xpdf13 мар. 2018 г.
- CVE-2022-3822231Наблюдать
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %xpdfreader · xpdf28 сент. 2022 г.
- CVE-2022-3892831Наблюдать
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %xpdfreader · xpdf21 сент. 2022 г.
- CVE-2022-3817131Наблюдать
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %xpdfreader · xpdf22 авг. 2022 г.
- CVE-2007-338730Наблюдать
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,
СредняяCVSS 6,8Эксплойта нетEPSS 9 %apple · cups30 июл. 2007 г.
- CVE-2021-3649330Наблюдать
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %xpdfreader · xpdf3 февр. 2023 г.
- CVE-2018-1636922Наблюдать
XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related
СредняяCVSS 5,5Эксплойта нетEPSS 2 %xpdfreader · xpdf2 сент. 2018 г.
- CVE-2018-1845422Наблюдать
CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf18 окт. 2018 г.
- CVE-2018-1845922Наблюдать
The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf18 окт. 2018 г.
- CVE-2018-1845822Наблюдать
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf18 окт. 2018 г.
- CVE-2018-1845722Наблюдать
The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf18 окт. 2018 г.
- CVE-2018-1845522Наблюдать
The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf18 окт. 2018 г.
- CVE-2018-1636822Наблюдать
SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf2 сент. 2018 г.
- CVE-2019-1001822Наблюдать
An issue was discovered in Xpdf 4.01.01.
СредняяCVSS 5,5Эксплойта нетEPSS 1 %xpdfreader · xpdf24 мар. 2019 г.