Show filters
135 Total Results
Displaying 61-70 of 135
Sort by:
Attacker Value
Unknown

CVE-2017-2626

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
0
Attacker Value
Unknown

CVE-2018-13988

Disclosure Date: July 25, 2018 (last updated November 27, 2024)
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
0
Attacker Value
Unknown

CVE-2018-14036

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
0
Attacker Value
Unknown

CVE-2017-18267

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
0
Attacker Value
Unknown

CVE-2017-18266

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
0
Attacker Value
Unknown

CVE-2018-10768

Disclosure Date: May 06, 2018 (last updated November 26, 2024)
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
0
Attacker Value
Unknown

CVE-2017-15131

Disclosure Date: January 09, 2018 (last updated November 26, 2024)
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.
0
Attacker Value
Unknown

CVE-2017-1000456

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
0
Attacker Value
Unknown

CVE-2017-15565

Disclosure Date: October 17, 2017 (last updated November 26, 2024)
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
0
Attacker Value
Unknown

CVE-2017-14976

Disclosure Date: October 02, 2017 (last updated November 26, 2024)
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.
0