Debian Mupdf vulnerabilities
49 known vulnerabilities affecting debian/mupdf.
Total CVEs
49
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM22LOW14
Vulnerabilities
Page 1 of 3
CVE-2017-5991P3LOWCVSS 7.5PoCfixed in mupdf 1.9a+ds1-4 (bookworm)2017
CVE-2017-5991 [HIGH] CVE-2017-5991: mupdf - An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3a...
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.
Scope: local
bookworm: resolved (fixed in 1.9a+ds1-4)
bullseye: resolved (fixed in 1.9a+ds1-4)
fork
debian
CVE-2014-2013P3HIGHCVSS 7.5PoCfixed in mupdf 1.3-2 (bookworm)2014
CVE-2014-2013 [HIGH] CVE-2014-2013: mupdf - Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c ...
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.
Scope: local
bookworm: resolved (fixed in 1.3-2)
bullseye: resolved (fixed in 1.3-2)
forky: resolved (fixed in 1.3-2)
si
debian
CVE-2017-6060P3LOWCVSS 7.8PoCfixed in mupdf 1.12.0+ds1-1 (bookworm)2017
CVE-2017-6060 [HIGH] CVE-2017-6060: mupdf - Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, In...
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.12.0+ds1-1)
bullseye: resolved (fixed in 1.12.0+ds1-1)
forky: resolved (fixed in 1.12.0+ds1-1)
sid: resolved (fixed in 1.12.0+ds1-1)
trixie: resolved (fixed in 1
debian
CVE-2012-5340P3HIGHCVSS 7.8PoCfixed in mupdf 1.2-2 (bookworm)2012
CVE-2012-5340 [HIGH] CVE-2012-5340: mupdf - SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow ...
SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.
Scope: local
bookworm: resolved (fixed in 1.2-2)
bullseye: resolved (fixed in 1.2-2)
forky: resolved (fixed in 1.2-2)
sid: resolved (fixed in 1.2-2)
trixie: resolved (fixed in 1.2-2)
debian
CVE-2016-6525P3CRITICALCVSS 9.8fixed in mupdf 1.9a+ds1-1.2 (bookworm)2016
CVE-2016-6525 [CRITICAL] CVE-2016-6525: mupdf - Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade...
Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array.
Scope: local
bookworm: resolved (fixed in 1.9a+ds1-1.2)
bullseye: resolved (fixed in 1.9a+ds1-1.2)
forky: resolved (fixed in 1.9a+ds1-1.2)
sid: resolved (fixed in
debian
CVE-2021-3407P3MEDIUMCVSS 5.5fixed in mupdf 1.17.0+ds1-1.3 (bookworm)2021
CVE-2021-3407 [MEDIUM] CVE-2021-3407: mupdf - A flaw was found in mupdf 1.18.0. Double free of object during linearization may...
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
Scope: local
bookworm: resolved (fixed in 1.17.0+ds1-1.3)
bullseye: resolved (fixed in 1.17.0+ds1-1.3)
forky: resolved (fixed in 1.17.0+ds1-1.3)
sid: resolved (fixed in 1.17.0+ds1-1.3)
trixie: resolved (fixed in 1.17.0+ds1-1.3)
debian
CVE-2019-13290P3HIGHCVSS 7.8fixed in mupdf 1.15.0+ds1-1 (bookworm)2019
CVE-2019-13290 [HIGH] CVE-2019-13290: mupdf - Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node ...
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.
Scope: local
bookworm: resolved (fixed in 1.15.0+ds1-1)
bullseye: resolved (fixed
debian
CVE-2026-25556P3LOWCVSS 5.9fixed in mupdf 1.27.0+ds1-3 (forky)2026
CVE-2026-25556 [MEDIUM] CVE-2026-25556: mupdf - MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_f...
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_dec
debian
CVE-2018-1000051P3HIGHCVSS 7.8fixed in mupdf 1.12.0+ds1-1 (bookworm)2018
CVE-2018-1000051 [HIGH] CVE-2018-1000051: mupdf - Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_...
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
Scope: local
bookworm: resolved (fixed in 1.12.0+ds1-1)
bullseye: resolved (fixed in 1.12.0+ds1-1)
forky: resolved (fixed in 1.12.0+ds1-1)
sid:
debian
CVE-2018-1000038P3HIGHCVSS 7.8fixed in mupdf 1.13.0+ds1-1 (bookworm)2018
CVE-2018-1000038 [HIGH] CVE-2018-1000038: mupdf - In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_loo...
In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.13.0+ds1-1)
bullseye: resolved (fixed in 1.13.0+ds1-1)
forky: resolved (fixed in 1.13.0+ds1-1)
sid: resolved (fixed in 1.13.0+ds1-1)
trixie:
debian
CVE-2025-55780P3HIGHCVSS 7.5fixed in mupdf 1.27.0+ds1-2 (forky)2025
CVE-2025-55780 [HIGH] CVE-2025-55780: mupdf - A null pointer dereference occurs in the function break_word_for_overflow_wrap()...
A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial nod
debian
CVE-2017-14686P3HIGHCVSS 7.8fixed in mupdf 1.11+ds1-1.1 (bookworm)2017
CVE-2017-14686 [HIGH] CVE-2017-14686: mupdf - Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial ...
Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.
Scope: local
boo
debian
CVE-2018-1000039P3MEDIUMCVSS 6.3fixed in mupdf 1.13.0+ds1-1 (bookworm)2018
CVE-2018-1000039 [MEDIUM] CVE-2018-1000039: mupdf - In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PD...
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.13.0+ds1-1)
bullseye: resolved (fixed in 1.13.0+ds1-1)
forky: resolved (fixed in 1.13.0+ds1-1)
sid: resolved (fixed in
debian
CVE-2020-16600P3HIGHCVSS 7.8fixed in mupdf 1.17.0+ds1-1 (bookworm)2020
CVE-2020-16600 [HIGH] CVE-2020-16600: mupdf - A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1....
A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.
Scope: local
bookworm: resolved (fixed in 1.17.0+ds1-1)
bullseye: resolved (fixed in 1.17.0+ds1-1)
fork
debian
CVE-2017-17866P4HIGHCVSS 7.8fixed in mupdf 1.12.0+ds1-1 (bookworm)2017
CVE-2017-17866 [HIGH] CVE-2017-17866: mupdf - pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes...
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.
Scope: local
bookworm: resolved (fixed in 1.12.0+ds1-1)
bullsey
debian
CVE-2017-15587P4HIGHCVSS 7.8fixed in mupdf 1.11+ds1-2 (bookworm)2017
CVE-2017-15587 [HIGH] CVE-2017-15587: mupdf - An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref....
An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.
Scope: local
bookworm: resolved (fixed in 1.11+ds1-2)
bullseye: resolved (fixed in 1.11+ds1-2)
forky: resolved (fixed in 1.11+ds1-2)
sid: resolved (fixed in 1.11+ds1-2)
trixie: resolved (fixed in 1.11+ds1-2)
debian
CVE-2017-14685P4HIGHCVSS 7.8fixed in mupdf 1.11+ds1-1.1 (bookworm)2017
CVE-2017-14685 [HIGH] CVE-2017-14685: mupdf - Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly hav...
Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.
Scope: loc
debian
CVE-2017-14687P4HIGHCVSS 7.8fixed in mupdf 1.11+ds1-1.1 (bookworm)2017
CVE-2017-14687 [HIGH] CVE-2017-14687: mupdf - Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly hav...
Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016cb4f" on Windows. This occurs because of mishandling of XML tag name comparisons.
Scope: local
bookworm: resolved (fixed in 1.11+ds1-1.1)
bul
debian
CVE-2025-46206P4MEDIUMCVSS 6.5fixed in mupdf 1.25.1+ds1-7 (forky)2025
CVE-2025-46206 [MEDIUM] CVE-2025-46206: mupdf - An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a den...
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
Scope: local
bookworm: open
bullseye: open
forky: resolved (fix
debian
CVE-2017-5896P4MEDIUMCVSS 5.5fixed in mupdf 1.9a+ds1-3 (bookworm)2017
CVE-2017-5896 [MEDIUM] CVE-2017-5896: mupdf - Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c ...
Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c in MuPDF 1.10a allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted image.
Scope: local
bookworm: resolved (fixed in 1.9a+ds1-3)
bullseye: resolved (fixed in 1.9a+ds1-3)
forky: resolved (fixed in 1.9a+ds1-3)
sid: resolved (fixed in 1.9a+ds1-3)
t
debian
1 / 3Next →