Show filters
175 Total Results
Displaying 91-100 of 175
Sort by:
Attacker Value
Unknown

CVE-2019-10020

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.
0
Attacker Value
Unknown

CVE-2019-9877

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2019-9878

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2019-9589

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2019-9587

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.
0
Attacker Value
Unknown

CVE-2019-9588

Disclosure Date: March 06, 2019 (last updated November 27, 2024)
There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2018-18651

Disclosure Date: October 25, 2018 (last updated November 27, 2024)
An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by large loop) via a specific pdf file, as demonstrated by pdftohtml. This is mainly caused by a large number after the /Count field in the file.
0
Attacker Value
Unknown

CVE-2018-18650

Disclosure Date: October 25, 2018 (last updated November 27, 2024)
An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow) via a crafted /Size value in a pdf file, as demonstrated by pdftohtml. This is mainly caused by the program attempting a malloc operation for a large amount of memory.
0
Attacker Value
Unknown

CVE-2018-18458

Disclosure Date: October 18, 2018 (last updated November 27, 2024)
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
0
Attacker Value
Unknown

CVE-2018-18456

Disclosure Date: October 18, 2018 (last updated November 27, 2024)
The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
0