Перейти к содержимому
Noroxi

Записи xpdfreader

82 опубликованных записей вендора xpdfreader.

Профиль для исследователя

Попали в KEV
1 · 1,2 %
С эксплойтом
1 · 1,2 %
Pre-auth RCE
1
С записью об исправлении
13,4 %
Медиана: публикация → KEV
71 дн.

Записи по годам

  1. 18
  2. 19
  3. 20
  4. 21
  5. 22
  6. 23
  7. 24

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

82 записей
  • CVE-2021-30860
    84Срочно

    An integer overflow was addressed with improved input validation.

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 76 %

    apple · ipados24 авг. 2021 г.

  • CVE-2012-2142
    32Наблюдать

    The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    freedesktop · poppler9 янв. 2020 г.

  • CVE-2010-3702
    31Наблюдать

    The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    apple · cups5 нояб. 2010 г.

  • CVE-2020-35376
    31Наблюдать

    Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::get

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    xpdfreader · xpdf26 дек. 2020 г.

  • CVE-2022-30524
    31Наблюдать

    There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters a

    ВысокаяCVSS 7,8Proof of conceptEPSS 2 %

    xpdfreader · xpdf9 мая 2022 г.

  • CVE-2018-11033
    31Наблюдать

    The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    xpdfreader · xpdf13 мая 2018 г.

  • CVE-2019-9878
    31Наблюдать

    There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pd

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    pdfalto project · pdfalto21 мар. 2019 г.

  • CVE-2022-33108
    31Наблюдать

    XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    xpdfreader · xpdf28 июн. 2022 г.

  • CVE-2019-9877
    31Наблюдать

    There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    xpdfreader · xpdf21 мар. 2019 г.

  • CVE-2020-24999
    31Наблюдать

    There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    xpdfreader · xpdf3 сент. 2020 г.

  • CVE-2020-24996
    31Наблюдать

    There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    xpdfreader · xpdf3 сент. 2020 г.

  • CVE-2018-8100
    31Наблюдать

    The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow a

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    xpdfreader · xpdf13 мар. 2018 г.

  • CVE-2022-38222
    31Наблюдать

    There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    xpdfreader · xpdf28 сент. 2022 г.

  • CVE-2022-38928
    31Наблюдать

    XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    xpdfreader · xpdf21 сент. 2022 г.

  • CVE-2022-38171
    31Наблюдать

    Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    xpdfreader · xpdf22 авг. 2022 г.

  • CVE-2007-3387
    30Наблюдать

    Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2,

    СредняяCVSS 6,8Эксплойта нетEPSS 9 %

    apple · cups30 июл. 2007 г.

  • CVE-2021-36493
    30Наблюдать

    Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf3 февр. 2023 г.

  • CVE-2018-16369
    22Наблюдать

    XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related

    СредняяCVSS 5,5Эксплойта нетEPSS 2 %

    xpdfreader · xpdf2 сент. 2018 г.

  • CVE-2018-18454
    22Наблюдать

    CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf18 окт. 2018 г.

  • CVE-2018-18459
    22Наблюдать

    The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf18 окт. 2018 г.

  • CVE-2018-18458
    22Наблюдать

    The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf18 окт. 2018 г.

  • CVE-2018-18457
    22Наблюдать

    The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) v

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf18 окт. 2018 г.

  • CVE-2018-18455
    22Наблюдать

    The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf18 окт. 2018 г.

  • CVE-2018-16368
    22Наблюдать

    SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf2 сент. 2018 г.

  • CVE-2019-10018
    22Наблюдать

    An issue was discovered in Xpdf 4.01.01.

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    xpdfreader · xpdf24 мар. 2019 г.