Show filters
172 Total Results
Displaying 31-40 of 172
Sort by:
Attacker Value
Unknown

CVE-2021-3185

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
Attacker Value
Unknown

CVE-2020-35702

Disclosure Date: December 25, 2020 (last updated February 22, 2025)
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects
Attacker Value
Unknown

CVE-2020-27778

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.
Attacker Value
Unknown

CVE-2020-16127

Disclosure Date: November 03, 2020 (last updated February 22, 2025)
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.
Attacker Value
Unknown

CVE-2020-16126

Disclosure Date: November 03, 2020 (last updated February 22, 2025)
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.
Attacker Value
Unknown

CVE-2020-12049

Disclosure Date: June 08, 2020 (last updated February 21, 2025)
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.
Attacker Value
Unknown

CVE-2012-2142

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
Attacker Value
Unknown

CVE-2010-4654

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
Attacker Value
Unknown

CVE-2010-4653

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
Attacker Value
Unknown

CVE-2019-20367

Disclosure Date: November 13, 2019 (last updated February 21, 2025)
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).