Show filters
135 Total Results
Displaying 41-50 of 135
Sort by:
Attacker Value
Unknown
CVE-2019-10872
Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
0
Attacker Value
Unknown
CVE-2019-10871
Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
0
Attacker Value
Unknown
CVE-2019-10873
Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
0
Attacker Value
Unknown
CVE-2019-9903
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
0
Attacker Value
Unknown
CVE-2019-9631
Disclosure Date: March 08, 2019 (last updated November 08, 2023)
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
0
Attacker Value
Unknown
CVE-2019-9543
Disclosure Date: March 01, 2019 (last updated November 27, 2024)
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
0
Attacker Value
Unknown
CVE-2019-9545
Disclosure Date: March 01, 2019 (last updated November 27, 2024)
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
0
Attacker Value
Unknown
CVE-2019-9200
Disclosure Date: February 26, 2019 (last updated November 08, 2023)
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2019-7310
Disclosure Date: February 03, 2019 (last updated November 08, 2023)
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.
0
Attacker Value
Unknown
CVE-2018-20662
Disclosure Date: January 03, 2019 (last updated November 08, 2023)
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
0