cbcvebase.

Debian Poppler vulnerabilities

128 known vulnerabilities affecting debian/poppler.

Total CVEs
128
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH22MEDIUM44LOW57

Vulnerabilities

Page 1 of 7
CVE-2008-2950P3MEDIUMCVSS 7.5PoCfixed in poppler 0.8.4-1.1 (bookworm)2008
CVE-2008-2950 [HIGH] CVE-2008-2950: poppler - The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier delete... The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.8.4-1.1) bullseye: resolved (fixed in 0.8.4-1.1) forky: resolved (fixed in 0.8.4-1.1)
debian
CVE-2013-4474P4LOWCVSS 5.0PoCfixed in poppler 0.18.4-9 (bookworm)2013
CVE-2013-4474 [MEDIUM] CVE-2013-4474: poppler - Format string vulnerability in the extractPages function in utils/pdfseparate.cc... Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename. Scope: local bookworm: resolved (fixed in 0.18.4-9) bullseye: resolved (fixed in 0.18.4-9) forky: resolved (fixed in 0.18.4-9) sid: resolved (fix
debian
CVE-2009-3608P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3608 [CRITICAL] CVE-2009-3608: poppler - Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3... Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.12.2-1) bul
debian
CVE-2009-3606P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3606 [CRITICAL] CVE-2009-3606: poppler - Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl... Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.12.2-1) bullseye: resolved (fixed in 0.12.2-1) forky: resolved (fix
debian
CVE-2009-0755P4LOWCVSS 5.0PoCfixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0755 [MEDIUM] CVE-2009-0755: poppler - The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remo... The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed in 0.10.6-1) trixie: resolved (fixed in 0.1
debian
CVE-2009-0756P4LOWCVSS 5.0PoCfixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0756 [MEDIUM] CVE-2009-0756: poppler - The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remo... The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in
debian
CVE-2011-0764P3LOWCVSS 6.8fixed in xpdf 3.02-9 (bookworm)2011
CVE-2011-0764 [MEDIUM] CVE-2011-0764: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc... t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: r
debian
CVE-2009-1182P3MEDIUMCVSS 7.5fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1182 [HIGH] CVE-2009-1182: poppler - Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, ... Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed in
debian
CVE-2019-9200P3HIGHCVSS 8.8fixed in poppler 0.71.0-4 (bookworm)2019
CVE-2019-9200 [HIGH] CVE-2019-9200: poppler - A heap-based buffer underwrite exists in ImageStream::getLine() located at Strea... A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.71.0-4) bullseye: r
debian
CVE-2009-3604P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3604 [CRITICAL] CVE-2009-3604: poppler - The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, ... The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-base
debian
CVE-2007-5392P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5392 [CRITICAL] CVE-2007-5392: cups - Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p1... Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fixed in 1.1.22-7) trixie: r
debian
CVE-2012-2142P3LOWCVSS 7.8fixed in poppler 0.18.4-7 (bookworm)2012
CVE-2012-2142 [HIGH] CVE-2012-2142: poppler - The error function in Error.cc in poppler before 0.21.4 allows remote attackers ... The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. Scope: local bookworm: resolved (fixed in 0.18.4-7) bullseye: resolved (fixed in 0.18.4-7) forky: resolved (fixed in 0.18.4-7) sid: resolved (fixed in 0.18.4-7) trixie: resolved (fixed in 0.18.4-
debian
CVE-2009-3603P3MEDIUMCVSS 5.0fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3603 [MEDIUM] CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3... Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplet
debian
CVE-2009-4035P3CRITICALCVSS 9.3fixed in poppler 0.5.1-1 (bookworm)2009
CVE-2009-4035 [CRITICAL] CVE-2009-4035: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kp... The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a
debian
CVE-2013-4473P3LOWCVSS 7.5fixed in poppler 0.18.4-9 (bookworm)2013
CVE-2013-4473 [HIGH] CVE-2013-4473: poppler - Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc... Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename. Scope: local bookworm: resolved (fixed in 0.18.4-9) bullseye: resolved (fixed in 0.18.4-9) forky: resolved (fixed in 0.18.4-9) sid: resolved (fi
debian
CVE-2007-5393P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5393 [CRITICAL] CVE-2007-5393: cups - Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream... Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fixed in 1.1.22
debian
CVE-2009-3607P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3607 [CRITICAL] CVE-2009-3607: poppler - Integer overflow in the create_surface_from_thumbnail_data function in glib/popp... Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. Scope: lo
debian
CVE-2007-4352P3HIGHCVSS 7.6fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-4352 [HIGH] CVE-2007-4352: cups - Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Strea... Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: re
debian
CVE-2015-8868P3HIGHCVSS 7.8fixed in poppler 0.38.0-3 (bookworm)2015
CVE-2015-8868 [HIGH] CVE-2015-8868: poppler - Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction funct... Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.38.0-3) bullseye:
debian
CVE-2018-21009P3HIGHCVSS 8.8fixed in poppler 0.69.0-2 (bookworm)2018
CVE-2018-21009 [HIGH] CVE-2018-21009: poppler - Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc... Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. Scope: local bookworm: resolved (fixed in 0.69.0-2) bullseye: resolved (fixed in 0.69.0-2) forky: resolved (fixed in 0.69.0-2) sid: resolved (fixed in 0.69.0-2) trixie: resolved (fixed in 0.69.0-2)
debian
Debian Poppler vulnerabilities | cvebase