Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-0755 — Poppler vulnerability

11 documents9 sources
Severity
5.0MEDIUMNVD
EPSS
23.2%
top 4.05%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 3
Latest updateMay 2

Description

The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

â–¶Debianfreedesktop/poppler< 0.10.6-1+3
â–¶NVDpoppler/poppler0.10.3+33

🔴Vulnerability Details

3
GHSA
GHSA-jmc7-m54g-vwh9: The FormWidgetChoice::loadDefaults function in Poppler before 0↗2022-05-02
â–¶
OSV
CVE-2009-0755: The FormWidgetChoice::loadDefaults function in Poppler before 0↗2009-03-03
â–¶
CVEList
CVE-2009-0755: The FormWidgetChoice::loadDefaults function in Poppler before 0↗2009-03-03
â–¶

💥Exploits & PoCs

1
Exploit-DB
Poppler 0.10.3 - Denial of Service↗2009-02-12
â–¶

📋Vendor Advisories

3
Ubuntu
poppler vulnerabilities↗2009-10-21
â–¶
Red Hat
poppler/evince: DoS via crafted PDF file↗2009-01-27
â–¶
Debian
CVE-2009-0755: poppler - The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remo...↗2009
â–¶

💬Community

2
Bugzilla
CVE-2009-1299 pulseaudio: information disclosure or DoS due to temporary directory handling↗2010-03-05
â–¶
Bugzilla
CVE-2009-0755 poppler/evince: DoS via crafted PDF file↗2009-03-03
â–¶
CVE-2009-0755 — Poppler vulnerability | cvebase