Show filters
175 Total Results
Displaying 121-130 of 175
Sort by:
Attacker Value
Unknown
CVE-2018-7175
Disclosure Date: February 15, 2018 (last updated November 26, 2024)
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
0
Attacker Value
Unknown
CVE-2018-7173
Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.
0
Attacker Value
Unknown
CVE-2018-7174
Disclosure Date: February 15, 2018 (last updated November 26, 2024)
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
0
Attacker Value
Unknown
CVE-2011-2902
Disclosure Date: January 30, 2018 (last updated November 26, 2024)
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
0
Attacker Value
Unknown
CVE-2011-1553
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-1554
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-1552
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-0764
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
0
Attacker Value
Unknown
CVE-2010-3704
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
0
Attacker Value
Unknown
CVE-2010-3702
Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
0