Show filters
172 Total Results
Displaying 41-50 of 172
Sort by:
Attacker Value
Unknown

CVE-2019-15682

Disclosure Date: October 30, 2019 (last updated November 27, 2024)
RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. These issues have been fixed in version 1.8.5
Attacker Value
Unknown

CVE-2018-21009

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
0
Attacker Value
Unknown

CVE-2019-14494

Disclosure Date: August 01, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
Attacker Value
Unknown

CVE-2019-9959

Disclosure Date: July 22, 2019 (last updated November 08, 2023)
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.
Attacker Value
Unknown

CVE-2019-12749

Disclosure Date: June 11, 2019 (last updated November 08, 2023)
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.
0
Attacker Value
Unknown

CVE-2019-12293

Disclosure Date: May 23, 2019 (last updated November 08, 2023)
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.
0
Attacker Value
Unknown

CVE-2019-11026

Disclosure Date: April 08, 2019 (last updated November 08, 2023)
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
Attacker Value
Unknown

CVE-2019-10872

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
0
Attacker Value
Unknown

CVE-2019-10871

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
0
Attacker Value
Unknown

CVE-2019-10873

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
0