Show filters
175 Total Results
Displaying 51-60 of 175
Sort by:
Attacker Value
Unknown
CVE-2020-35376
Disclosure Date: December 26, 2020 (last updated February 22, 2025)
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
0
Attacker Value
Unknown
CVE-2020-25725
Disclosure Date: November 21, 2020 (last updated February 22, 2025)
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font.
0
Attacker Value
Unknown
CVE-2020-24999
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2020-24996
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2012-2142
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2010-0207
Disclosure Date: October 30, 2019 (last updated November 27, 2024)
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
0
Attacker Value
Unknown
CVE-2010-0206
Disclosure Date: October 30, 2019 (last updated November 27, 2024)
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
0
Attacker Value
Unknown
CVE-2019-17064
Disclosure Date: October 01, 2019 (last updated November 08, 2023)
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
0
Attacker Value
Unknown
CVE-2019-16927
Disclosure Date: September 27, 2019 (last updated November 27, 2024)
Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.
0
Attacker Value
Unknown
CVE-2019-16115
Disclosure Date: September 08, 2019 (last updated November 27, 2024)
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact.
0