Show filters
135 Total Results
Displaying 111-120 of 135
Sort by:
Attacker Value
Unknown

CVE-2013-4473

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.
0
Attacker Value
Unknown

CVE-2013-4474

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.
0
Attacker Value
Unknown

CVE-2013-2168

Disclosure Date: July 03, 2013 (last updated December 28, 2023)
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
0
Attacker Value
Unknown

CVE-2013-1788

Disclosure Date: April 09, 2013 (last updated October 05, 2023)
poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc.
0
Attacker Value
Unknown

CVE-2013-1790

Disclosure Date: April 09, 2013 (last updated October 05, 2023)
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
0
Attacker Value
Unknown

CVE-2013-1789

Disclosure Date: April 09, 2013 (last updated October 05, 2023)
splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.
0
Attacker Value
Unknown

CVE-2013-0292

Disclosure Date: March 05, 2013 (last updated October 05, 2023)
The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.
0
Attacker Value
Unknown

CVE-2012-3524

Disclosure Date: September 18, 2012 (last updated November 08, 2023)
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
0
Attacker Value
Unknown

CVE-2012-4425

Disclosure Date: September 18, 2012 (last updated November 08, 2023)
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
0
Attacker Value
Unknown

CVE-2011-4349

Disclosure Date: December 10, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in (1) cd-mapping-db.c and (2) cd-device-db.c in colord before 0.1.15 allow local users to execute arbitrary SQL commands via vectors related to color devices and (a) device id, (b) property, or (c) profile id.
0