Search CVE reports


Toggle filters

81 – 90 of 205 results


CVE-2019-9589

Low priority
Ignored

There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an...

6 affected packages

xpdf, ipe, libextractor, poppler, texlive-bin, utopia-documents

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not in release Not affected
ipe Not affected Not affected Not affected
libextractor Not affected Not affected Not affected
poppler Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release
Show less packages

CVE-2019-9588

Low priority
Vulnerable

There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service...

6 affected packages

texlive-bin, libextractor, ipe, xpdf, poppler, utopia-documents

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
libextractor Not affected Not affected Not affected Not affected
ipe Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9587

Negligible priority
Vulnerable

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service...

6 affected packages

texlive-bin, ipe, libextractor, poppler, utopia-documents, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
ipe Not affected Not affected Not affected Not affected
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9545

Negligible priority
Vulnerable

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2019-9543

Negligible priority
Vulnerable

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2019-9200

Medium priority
Fixed

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2019-7310

Medium priority
Fixed

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20662

Low priority
Fixed

In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20650

Low priority
Fixed

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20551

Low priority
Fixed

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages