cbcvebase.

Debian Mupdf vulnerabilities

49 known vulnerabilities affecting debian/mupdf.

Total CVEs
49
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM22LOW14

Vulnerabilities

Page 3 of 3
CVE-2018-6192P4MEDIUMCVSS 5.5fixed in mupdf 1.13.0+ds1-1 (bookworm)2018
CVE-2018-6192 [MEDIUM] CVE-2018-6192: mupdf - In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows... In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file. Scope: local bookworm: resolved (fixed in 1.13.0+ds1-1) bullseye: resolved (fixed in 1.13.0+ds1-1) forky: resolved (fixed in 1.13.0+ds1-1) sid: resolved (fixed in 1.13.0+ds
debian
CVE-2018-5686P4MEDIUMCVSS 5.5fixed in mupdf 1.13.0+ds1-1 (bookworm)2018
CVE-2018-5686 [MEDIUM] CVE-2018-5686: mupdf - In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in... In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file. Scope: local bookworm: resolved (fixed in 1.13.0+ds1-1) bullseye: resolved (fixed in 1.13.0+ds1-1) forky: r
debian
CVE-2016-8674P4MEDIUMCVSS 5.5fixed in mupdf 1.9a+ds1-2 (bookworm)2016
CVE-2016-8674 [MEDIUM] CVE-2016-8674: mupdf - The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attac... The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file. Scope: local bookworm: resolved (fixed in 1.9a+ds1-2) bullseye: resolved (fixed in 1.9a+ds1-2) forky: resolved (fixed in 1.9a+ds1-2) sid: resolved (fixed in 1.9a+ds1-2) trixie: resolved (fixed in 1
debian
CVE-2024-46657P4LOWCVSS 5.5fixed in mupdf 1.25.1+ds1-5 (forky)2024
CVE-2024-46657 [MEDIUM] CVE-2024-46657: mupdf - Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault vi... Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.25.1+ds1-5) sid: resolved (fixed in 1.25.1+ds1-5) trixie: resolved (fixed in 1.25.1+d
debian
CVE-2018-19882P4LOWCVSS 5.5fixed in mupdf 1.15.0+ds1-1 (bookworm)2018
CVE-2018-19882 [MEDIUM] CVE-2018-19882: mupdf - In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remo... In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl. Scope: local bookworm: resolved (fixed in 1.15.0+ds1-1) bullseye: resolved (fixed in 1.15.0+ds1-1) forky: resolved (fixed in 1.15.0+ds1
debian
CVE-2018-19777P4LOWCVSS 5.5fixed in mupdf 1.15.0+ds1-1 (bookworm)2018
CVE-2018-19777 [MEDIUM] CVE-2018-19777: mupdf - In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_t... In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool. Scope: local bookworm: resolved (fixed in 1.15.0+ds1-1) bullseye: resolved (fixed in 1.15.0+ds1-1) forky: resolved (fixed in 1.15.0+ds1-1) sid: resolved (fixed in 1.15.0+ds1-1) trixie: resolved (fixed in 1.15.0+ds1-1)
debian
CVE-2018-10289P4LOWCVSS 5.5fixed in mupdf 1.13.0+ds1-3 (bookworm)2018
CVE-2018-10289 [MEDIUM] CVE-2018-10289: mupdf - In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the ... In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file. Scope: local bookworm: resolved (fixed in 1.13.0+ds1-3) bullseye: resolved (fixed in 1.13.0+ds1-3) forky: resolved (fixed in 1.13.0+ds1-3) sid: resolved (fixed i
debian
CVE-2018-1000036P4LOWCVSS 5.5fixed in mupdf 1.14.0+ds1-1 (bookworm)2018
CVE-2018-1000036 [MEDIUM] CVE-2018-1000036: mupdf - In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser all... In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file. Scope: local bookworm: resolved (fixed in 1.14.0+ds1-1) bullseye: resolved (fixed in 1.14.0+ds1-1) forky: resolved (fixed in 1.14.0+ds1-1) sid: resolved (fixed in 1.14.0+ds1-1) trixie: resolved (fixed in 1.
debian
CVE-2023-31794P4LOWCVSS 5.5fixed in mupdf 1.22.1+ds1-1 (forky)2023
CVE-2023-31794 [MEDIUM] CVE-2023-31794: mupdf - MuPDF v1.21.1 was discovered to contain an infinite recursion in the component p... MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.22.1+ds1-1) sid: resolved (fixed in 1.22.1+ds1-1) trixie: resolved (fixed in 1.22.1+ds1-1)
debian
Debian Mupdf vulnerabilities | cvebase