Freedesktop kayıtları
freedesktop üreticisine ait 150 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,7
- Silahlaştırılmış
- 1 · %0,7
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %90,7
- Yayından KEV’e ortanca
- 71 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation19
- CWE-476 NULL Pointer Dereference16
- CWE-125 Out-of-bounds Read13
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer12
- CWE-190 Integer Overflow or Wraparound11
- CWE-674 Uncontrolled Recursion6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
150 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
84Hemen | CVE-2021-30860Silahlaştırılmış | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | Yüksek7,8 | KEV | %76,0 | 24 Ağu 2021 |
40Planlayın | CVE-2019-9631İstismar yok | Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.freedesktop · poppler · CWE-125 | Kritik9,8 | — | %3,5 | 8 Mar 2019 |
40Planlayın | CVE-2016-2090İstismar yok | Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whifedoraproject · fedora · CWE-119 | Kritik9,8 | — | %3,2 | 13 Oca 2017 |
40Planlayın | CVE-2021-3185İstismar yok | A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could causefreedesktop · gst-plugins-bad · CWE-120 | Kritik9,8 | — | %2,4 | 26 Oca 2021 |
39İzleyin | CVE-2026-50292İstismar yok | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrfreedesktop · libinput · CWE-93 | Kritik9,8 | — | %0,5 | 4 Haz 2026 |
37İzleyin | CVE-2019-20367İstismar yok | nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).freedesktop · libbsd · CWE-125 | Kritik9,1 | — | %2,8 | 8 Oca 2020 |
36İzleyin | CVE-2017-2820İstismar yok | An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.freedesktop · poppler · CWE-190 | Yüksek8,8 | — | %4,4 | 12 Tem 2017 |
36İzleyin | CVE-2019-9200İstismar yok | A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered bfreedesktop · poppler · CWE-787 | Yüksek8,8 | — | %3,5 | 26 Şub 2019 |
36İzleyin | CVE-2019-9543İstismar yok | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | Yüksek8,8 | — | %3,3 | 1 Mar 2019 |
36İzleyin | CVE-2015-1877İstismar yok | The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, debian · debian linux · CWE-77 | Yüksek8,8 | — | %3,2 | 2 Haz 2021 |
36İzleyin | CVE-2017-2814İstismar yok | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.freedesktop · poppler · CWE-119 | Yüksek8,8 | — | %2,7 | 12 Tem 2017 |
36İzleyin | CVE-2019-10872İstismar yok | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-125 | Yüksek8,8 | — | %2,7 | 5 Nis 2019 |
36İzleyin | CVE-2017-18266İstismar yok | The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSfreedesktop · xdg-utils · CWE-74 | Yüksek8,8 | — | %2,5 | 10 May 2018 |
36İzleyin | CVE-2019-12293İstismar yok | In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heightsfreedesktop · poppler · CWE-125 | Yüksek8,8 | — | %2,1 | 23 May 2019 |
36İzleyin | CVE-2017-15565İstismar yok | In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF documefreedesktop · poppler · CWE-476 | Yüksek8,8 | — | %2,1 | 17 Eki 2017 |
36İzleyin | CVE-2017-2818İstismar yok | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.freedesktop · poppler · CWE-119 | Yüksek8,8 | — | %2,0 | 12 Tem 2017 |
36İzleyin | CVE-2017-1000456İstismar yok | freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.freedesktop · poppler · CWE-119 | Yüksek8,8 | — | %2,0 | 2 Oca 2018 |
36İzleyin | CVE-2018-21009İstismar yok | Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.freedesktop · poppler · CWE-190 | Yüksek8,8 | — | %1,9 | 5 Eyl 2019 |
36İzleyin | CVE-2019-9545İstismar yok | An issue was discovered in Poppler 0.74.0.freedesktop · poppler · CWE-674 | Yüksek8,8 | — | %1,8 | 1 Mar 2019 |
36İzleyin | CVE-2026-46470İstismar yok | An issue was discovered in GStreamer gst-plugins-good before 1.28.2.freedesktop · gst-plugins-good · CWE-369 | Kritik9,1 | — | %0,4 | 14 May 2026 |
35İzleyin | CVE-2026-35093İstismar yok | Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode pluginsfreedesktop · libinput · CWE-94 | Yüksek8,8 | — | %0,2 | 1 Nis 2026 |
32İzleyin | CVE-2013-4473İstismar yok | Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause afreedesktop · poppler · CWE-119 | Yüksek7,5 | — | %7,1 | 23 Kas 2013 |
32İzleyin | CVE-2015-8868İstismar yok | Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to causfedoraproject · fedora · CWE-119 | Yüksek7,8 | — | %4,6 | 6 May 2016 |
32İzleyin | CVE-2012-2142İstismar yok | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapefreedesktop · poppler | Yüksek7,8 | — | %2,9 | 9 Oca 2020 |
32İzleyin | CVE-2019-7310İstismar yok | In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remotfreedesktop · poppler · CWE-125 | Yüksek7,8 | — | %2,1 | 2 Şub 2019 |
- CVE-2021-3086084Hemen
An integer overflow was addressed with improved input validation.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %76apple · ipados24 Ağu 2021
- CVE-2019-963140Planlayın
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
KritikCVSS 9,8İstismar yokEPSS %4freedesktop · poppler8 Mar 2019
- CVE-2016-209040Planlayın
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whi
KritikCVSS 9,8İstismar yokEPSS %3fedoraproject · fedora13 Oca 2017
- CVE-2021-318540Planlayın
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause
KritikCVSS 9,8İstismar yokEPSS %2freedesktop · gst-plugins-bad26 Oca 2021
- CVE-2026-5029239İzleyin
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr
KritikCVSS 9,8İstismar yokEPSS %1freedesktop · libinput4 Haz 2026
- CVE-2019-2036737İzleyin
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
KritikCVSS 9,1İstismar yokEPSS %3freedesktop · libbsd8 Oca 2020
- CVE-2017-282036İzleyin
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.
YüksekCVSS 8,8İstismar yokEPSS %4freedesktop · poppler12 Tem 2017
- CVE-2019-920036İzleyin
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered b
YüksekCVSS 8,8İstismar yokEPSS %3freedesktop · poppler26 Şub 2019
- CVE-2019-954336İzleyin
An issue was discovered in Poppler 0.74.0.
YüksekCVSS 8,8İstismar yokEPSS %3freedesktop · poppler1 Mar 2019
- CVE-2015-187736İzleyin
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables,
YüksekCVSS 8,8İstismar yokEPSS %3debian · debian linux2 Haz 2021
- CVE-2017-281436İzleyin
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
YüksekCVSS 8,8İstismar yokEPSS %3freedesktop · poppler12 Tem 2017
- CVE-2019-1087236İzleyin
An issue was discovered in Poppler 0.74.0.
YüksekCVSS 8,8İstismar yokEPSS %3freedesktop · poppler5 Nis 2019
- CVE-2017-1826636İzleyin
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWS
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · xdg-utils10 May 2018
- CVE-2019-1229336İzleyin
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · poppler23 May 2019
- CVE-2017-1556536İzleyin
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF docume
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · poppler17 Eki 2017
- CVE-2017-281836İzleyin
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · poppler12 Tem 2017
- CVE-2017-100045636İzleyin
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · poppler2 Oca 2018
- CVE-2018-2100936İzleyin
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · poppler5 Eyl 2019
- CVE-2019-954536İzleyin
An issue was discovered in Poppler 0.74.0.
YüksekCVSS 8,8İstismar yokEPSS %2freedesktop · poppler1 Mar 2019
- CVE-2026-4647036İzleyin
An issue was discovered in GStreamer gst-plugins-good before 1.28.2.
KritikCVSS 9,1İstismar yokEPSS %0freedesktop · gst-plugins-good14 May 2026
- CVE-2026-3509335İzleyin
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
YüksekCVSS 8,8İstismar yokEPSS %0freedesktop · libinput1 Nis 2026
- CVE-2013-447332İzleyin
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a
YüksekCVSS 7,5İstismar yokEPSS %7freedesktop · poppler23 Kas 2013
- CVE-2015-886832İzleyin
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to caus
YüksekCVSS 7,8İstismar yokEPSS %5fedoraproject · fedora6 May 2016
- CVE-2012-214232İzleyin
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape
YüksekCVSS 7,8İstismar yokEPSS %3freedesktop · poppler9 Oca 2020
- CVE-2019-731032İzleyin
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remot
YüksekCVSS 7,8İstismar yokEPSS %2freedesktop · poppler2 Şub 2019