Search CVE reports


Toggle filters

151 – 160 of 203 results


CVE-2010-5110

Low priority
Ignored

DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2013-4472

Medium priority
Not affected

The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

4 affected packages

ipe, libextractor, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe
libextractor
poppler
xpdf
Show less packages

CVE-2013-7296

Low priority
Ignored

The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2013-4474

Negligible priority

Some fixes available 1 of 4

Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2013-4473

Negligible priority

Some fixes available 1 of 4

Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2013-1790

Medium priority

Some fixes available 4 of 5

poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2013-1789

Low priority

Some fixes available 4 of 5

splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask,...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2013-1788

Medium priority

Some fixes available 4 of 5

poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc,...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler
Show less packages

CVE-2010-3704

Medium priority

Some fixes available 9 of 76

The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to...

11 affected packages

gpdf, ipe, koffice, poppler, kdegraphics...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpdf Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
koffice Not in release Not in release Not in release Not in release
poppler Not affected Not affected Not affected Not affected
kdegraphics Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release
tetex-bin Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
Show all 11 packages Show less packages

CVE-2010-3703

Medium priority

Some fixes available 4 of 73

The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a...

11 affected packages

kdegraphics, gpdf, ipe, pdfkit.framework, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kdegraphics Not in release Not in release Not in release Not in release
gpdf Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pdfkit.framework Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected
koffice Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release
poppler Not affected Not affected Not affected Not affected
tetex-bin Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
Show all 11 packages Show less packages