Search CVE reports


Toggle filters

81 – 90 of 203 results


CVE-2019-9587

Negligible priority
Vulnerable

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service...

6 affected packages

texlive-bin, ipe, libextractor, poppler, utopia-documents, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
ipe Not affected Not affected Not affected Not affected
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9545

Negligible priority
Vulnerable

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2019-9543

Negligible priority
Vulnerable

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2019-9200

Medium priority
Fixed

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2019-7310

Medium priority
Fixed

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20662

Low priority
Fixed

In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20650

Low priority
Fixed

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20551

Low priority
Fixed

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-20481

Medium priority
Fixed

XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h...

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages

CVE-2018-19149

Low priority
Fixed

Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed
Show less packages