Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown
CVE-2022-38227
Disclosure Date: August 16, 2022 (last updated October 08, 2023)
XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp.
0
Attacker Value
Unknown
CVE-2012-2142
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2010-0207
Disclosure Date: October 30, 2019 (last updated November 27, 2024)
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
0
Attacker Value
Unknown
CVE-2010-0206
Disclosure Date: October 30, 2019 (last updated November 27, 2024)
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
0
Attacker Value
Unknown
CVE-2011-1553
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-1554
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-1552
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-0764
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
0
Attacker Value
Unknown
CVE-2010-3704
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
0
Attacker Value
Unknown
CVE-2010-3702
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
0