İçeriğe atla
Noroxi

Freedesktop kayıtları

freedesktop üreticisine ait 150 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %0,7
Silahlaştırılmış
1 · %0,7
Pre-auth RCE
6
Düzeltme kaydı olan
%90,7
Yayından KEV’e ortanca
71 gün

Tüm kayıtlar

150 kayıt
  • An integer overflow was addressed with improved input validation.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %76

    apple · ipados24 Ağu 2021

  • CVE-2019-9631
    40Planlayın

    Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

    KritikCVSS 9,8İstismar yokEPSS %4

    freedesktop · poppler8 Mar 2019

  • CVE-2016-2090
    40Planlayın

    Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, whi

    KritikCVSS 9,8İstismar yokEPSS %3

    fedoraproject · fedora13 Oca 2017

  • CVE-2021-3185
    40Planlayın

    A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause

    KritikCVSS 9,8İstismar yokEPSS %2

    freedesktop · gst-plugins-bad26 Oca 2021

  • CVE-2026-50292
    39İzleyin

    In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitr

    KritikCVSS 9,8İstismar yokEPSS %1

    freedesktop · libinput4 Haz 2026

  • CVE-2019-20367
    37İzleyin

    nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

    KritikCVSS 9,1İstismar yokEPSS %3

    freedesktop · libbsd8 Oca 2020

  • CVE-2017-2820
    36İzleyin

    An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.

    YüksekCVSS 8,8İstismar yokEPSS %4

    freedesktop · poppler12 Tem 2017

  • CVE-2019-9200
    36İzleyin

    A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered b

    YüksekCVSS 8,8İstismar yokEPSS %3

    freedesktop · poppler26 Şub 2019

  • CVE-2019-9543
    36İzleyin

    An issue was discovered in Poppler 0.74.0.

    YüksekCVSS 8,8İstismar yokEPSS %3

    freedesktop · poppler1 Mar 2019

  • CVE-2015-1877
    36İzleyin

    The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables,

    YüksekCVSS 8,8İstismar yokEPSS %3

    debian · debian linux2 Haz 2021

  • CVE-2017-2814
    36İzleyin

    An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.

    YüksekCVSS 8,8İstismar yokEPSS %3

    freedesktop · poppler12 Tem 2017

  • CVE-2019-10872
    36İzleyin

    An issue was discovered in Poppler 0.74.0.

    YüksekCVSS 8,8İstismar yokEPSS %3

    freedesktop · poppler5 Nis 2019

  • CVE-2017-18266
    36İzleyin

    The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWS

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · xdg-utils10 May 2018

  • CVE-2019-12293
    36İzleyin

    In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · poppler23 May 2019

  • CVE-2017-15565
    36İzleyin

    In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF docume

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · poppler17 Eki 2017

  • CVE-2017-2818
    36İzleyin

    An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · poppler12 Tem 2017

  • freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · poppler2 Oca 2018

  • CVE-2018-21009
    36İzleyin

    Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · poppler5 Eyl 2019

  • CVE-2019-9545
    36İzleyin

    An issue was discovered in Poppler 0.74.0.

    YüksekCVSS 8,8İstismar yokEPSS %2

    freedesktop · poppler1 Mar 2019

  • CVE-2026-46470
    36İzleyin

    An issue was discovered in GStreamer gst-plugins-good before 1.28.2.

    KritikCVSS 9,1İstismar yokEPSS %0

    freedesktop · gst-plugins-good14 May 2026

  • CVE-2026-35093
    35İzleyin

    Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins

    YüksekCVSS 8,8İstismar yokEPSS %0

    freedesktop · libinput1 Nis 2026

  • CVE-2013-4473
    32İzleyin

    Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a

    YüksekCVSS 7,5İstismar yokEPSS %7

    freedesktop · poppler23 Kas 2013

  • CVE-2015-8868
    32İzleyin

    Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to caus

    YüksekCVSS 7,8İstismar yokEPSS %5

    fedoraproject · fedora6 May 2016

  • CVE-2012-2142
    32İzleyin

    The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape

    YüksekCVSS 7,8İstismar yokEPSS %3

    freedesktop · poppler9 Oca 2020

  • CVE-2019-7310
    32İzleyin

    In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remot

    YüksekCVSS 7,8İstismar yokEPSS %2

    freedesktop · poppler2 Şub 2019