Show filters
175 Total Results
Displaying 71-80 of 175
Sort by:
Attacker Value
Unknown

CVE-2019-13291

Disclosure Date: July 04, 2019 (last updated November 27, 2024)
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.
0
Attacker Value
Unknown

CVE-2019-13288

Disclosure Date: July 04, 2019 (last updated November 27, 2024)
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
0
Attacker Value
Unknown

CVE-2019-13289

Disclosure Date: July 04, 2019 (last updated November 27, 2024)
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.
0
Attacker Value
Unknown

CVE-2019-13286

Disclosure Date: July 04, 2019 (last updated November 08, 2023)
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.
Attacker Value
Unknown

CVE-2019-13281

Disclosure Date: July 04, 2019 (last updated November 08, 2023)
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an information leak, or possibly unspecified other impact.
Attacker Value
Unknown

CVE-2019-13283

Disclosure Date: July 04, 2019 (last updated November 08, 2023)
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Attacker Value
Unknown

CVE-2019-13282

Disclosure Date: July 04, 2019 (last updated November 08, 2023)
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Attacker Value
Unknown

CVE-2019-12958

Disclosure Date: June 25, 2019 (last updated November 08, 2023)
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.
0
Attacker Value
Unknown

CVE-2019-12957

Disclosure Date: June 25, 2019 (last updated November 08, 2023)
In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Attacker Value
Unknown

CVE-2019-12515

Disclosure Date: June 02, 2019 (last updated November 08, 2023)
There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service.
0