Show filters
230 Total Results
Displaying 141-150 of 230
Sort by:
Attacker Value
Unknown

CVE-2016-8729

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential code execution. An attacker can specially craft a PDF and send to the victim to trigger this vulnerability.
Attacker Value
Unknown

CVE-2016-8728

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
Attacker Value
Unknown

CVE-2016-9601

Disclosure Date: April 24, 2018 (last updated November 08, 2023)
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.
0
Attacker Value
Unknown

CVE-2018-10289

Disclosure Date: April 22, 2018 (last updated September 13, 2024)
In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.
Attacker Value
Unknown

CVE-2018-10194

Disclosure Date: April 18, 2018 (last updated November 08, 2023)
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
0
Attacker Value
Unknown

CVE-2018-1000051

Disclosure Date: February 09, 2018 (last updated September 12, 2024)
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
0
Attacker Value
Unknown

CVE-2018-6544

Disclosure Date: February 02, 2018 (last updated November 08, 2023)
pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.
0
Attacker Value
Unknown

CVE-2018-5759

Disclosure Date: January 24, 2018 (last updated November 08, 2023)
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file.
0
Attacker Value
Unknown

CVE-2018-6192

Disclosure Date: January 24, 2018 (last updated September 12, 2024)
In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.
0
Attacker Value
Unknown

CVE-2018-6191

Disclosure Date: January 24, 2018 (last updated November 08, 2023)
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.
0