Show filters
135 Total Results
Displaying 91-100 of 135
Sort by:
Attacker Value
Unknown
CVE-2017-7511
Disclosure Date: May 30, 2017 (last updated November 26, 2024)
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.
0
Attacker Value
Unknown
CVE-2017-9083
Disclosure Date: May 19, 2017 (last updated November 26, 2024)
poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.
0
Attacker Value
Unknown
CVE-2017-6355
Disclosure Date: March 10, 2017 (last updated November 26, 2024)
Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (process crash) via crafted pkt_length and offlen values, which trigger an out-of-bounds access.
0
Attacker Value
Unknown
CVE-2016-2568
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
0
Attacker Value
Unknown
CVE-2016-2090
Disclosure Date: January 13, 2017 (last updated November 08, 2023)
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2015-8868
Disclosure Date: May 06, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.
0
Attacker Value
Unknown
CVE-2015-0245
Disclosure Date: February 13, 2015 (last updated December 28, 2023)
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.
0
Attacker Value
Unknown
CVE-2014-7824
Disclosure Date: November 18, 2014 (last updated December 28, 2023)
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
0
Attacker Value
Unknown
CVE-2014-3636
Disclosure Date: October 25, 2014 (last updated December 28, 2023)
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.
0
Attacker Value
Unknown
CVE-2014-3638
Disclosure Date: September 22, 2014 (last updated December 28, 2023)
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.
0