Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2022-38928

Disclosure Date: September 21, 2022 (last updated October 08, 2023)
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
Attacker Value
Unknown

CVE-2022-36561

Disclosure Date: August 30, 2022 (last updated October 08, 2023)
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
Attacker Value
Unknown

CVE-2022-33108

Disclosure Date: June 28, 2022 (last updated October 07, 2023)
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
Attacker Value
Unknown

CVE-2022-30775

Disclosure Date: May 16, 2022 (last updated October 07, 2023)
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.
Attacker Value
Unknown

CVE-2022-38171

Disclosure Date: April 19, 2022 (last updated November 29, 2024)
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).