Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown
CVE-2018-19882
Disclosure Date: December 06, 2018 (last updated November 08, 2023)
In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.
0
Attacker Value
Unknown
CVE-2018-19777
Disclosure Date: November 30, 2018 (last updated November 08, 2023)
In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.
0
Attacker Value
Unknown
CVE-2018-18662
Disclosure Date: October 26, 2018 (last updated September 13, 2024)
There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
0
Attacker Value
Unknown
CVE-2018-16648
Disclosure Date: September 06, 2018 (last updated September 13, 2024)
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.
0
Attacker Value
Unknown
CVE-2018-16647
Disclosure Date: September 06, 2018 (last updated September 13, 2024)
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.
0
Attacker Value
Unknown
CVE-2016-8728
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-10289
Disclosure Date: April 22, 2018 (last updated September 13, 2024)
In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.
0
Attacker Value
Unknown
CVE-2018-1000051
Disclosure Date: February 09, 2018 (last updated September 12, 2024)
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
0
Attacker Value
Unknown
CVE-2018-6544
Disclosure Date: February 02, 2018 (last updated November 08, 2023)
pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.
0
Attacker Value
Unknown
CVE-2018-6192
Disclosure Date: January 24, 2018 (last updated September 12, 2024)
In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.
0