Show filters
54 Total Results
Displaying 1-10 of 54
Sort by:
Attacker Value
Unknown
CVE-2018-18688
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.
0
Attacker Value
Unknown
CVE-2019-16088
Disclosure Date: September 06, 2019 (last updated November 27, 2024)
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
0
Attacker Value
Unknown
CVE-2012-4337
Disclosure Date: August 23, 2012 (last updated October 04, 2023)
Foxit Reader before 5.3 on Windows XP and Windows 7 allows remote attackers to execute arbitrary code via a PDF document with a crafted attachment that triggers calculation of a negative number during processing of cross references.
0
Attacker Value
Unknown
CVE-2012-4363
Disclosure Date: August 21, 2012 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Adobe Reader through 10.1.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, related to "sixteen more crashes affecting Windows, OS X, or both systems."
0
Attacker Value
Unknown
CVE-2012-2648
Disclosure Date: August 07, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the GoodReader app 3.16 and earlier for iOS on the iPad, and 3.15.1 and earlier for iOS on the iPhone and iPod touch, allows remote attackers to inject arbitrary web script or HTML via vectors involving use of this app in conjunction with a web browser.
0
Attacker Value
Unknown
CVE-2011-3691
Disclosure Date: September 27, 2011 (last updated October 04, 2023)
Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.
0
Attacker Value
Unknown
CVE-2011-1908
Disclosure Date: June 24, 2011 (last updated October 04, 2023)
Integer overflow in the Type 1 font decoder in the FreeType engine in Foxit Reader before 4.0.0.0619 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font in a PDF document.
0
Attacker Value
Unknown
CVE-2011-1553
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-1554
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
0
Attacker Value
Unknown
CVE-2011-1552
Disclosure Date: March 31, 2011 (last updated October 04, 2023)
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
0