Show filters
135 Total Results
Displaying 41-50 of 135
Sort by:
Attacker Value
Unknown

CVE-2019-10872

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
0
Attacker Value
Unknown

CVE-2019-10871

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
0
Attacker Value
Unknown

CVE-2019-10873

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
0
Attacker Value
Unknown

CVE-2019-9903

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
Attacker Value
Unknown

CVE-2019-9631

Disclosure Date: March 08, 2019 (last updated November 08, 2023)
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
0
Attacker Value
Unknown

CVE-2019-9543

Disclosure Date: March 01, 2019 (last updated November 27, 2024)
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
0
Attacker Value
Unknown

CVE-2019-9545

Disclosure Date: March 01, 2019 (last updated November 27, 2024)
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
0
Attacker Value
Unknown

CVE-2019-9200

Disclosure Date: February 26, 2019 (last updated November 08, 2023)
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2019-7310

Disclosure Date: February 03, 2019 (last updated November 08, 2023)
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.
Attacker Value
Unknown

CVE-2018-20662

Disclosure Date: January 03, 2019 (last updated November 08, 2023)
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.