Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2019-10872

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
0
Attacker Value
Unknown

CVE-2019-10871

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
0
Attacker Value
Unknown

CVE-2019-10873

Disclosure Date: April 05, 2019 (last updated November 08, 2023)
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
0
Attacker Value
Unknown

CVE-2019-9903

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
Attacker Value
Unknown

CVE-2019-9631

Disclosure Date: March 08, 2019 (last updated November 08, 2023)
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
0
Attacker Value
Unknown

CVE-2019-9543

Disclosure Date: March 01, 2019 (last updated November 27, 2024)
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
0
Attacker Value
Unknown

CVE-2019-9545

Disclosure Date: March 01, 2019 (last updated November 27, 2024)
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
0
Attacker Value
Unknown

CVE-2019-9200

Disclosure Date: February 26, 2019 (last updated November 08, 2023)
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
0