cbcvebase.

Debian Poppler vulnerabilities

128 known vulnerabilities affecting debian/poppler.

Total CVEs
128
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH22MEDIUM44LOW57

Vulnerabilities

Page 2 of 7
CVE-2009-1180P3MEDIUMCVSS 6.8fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1180 [MEDIUM] CVE-2009-1180: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fi
debian
CVE-2007-3387P3LOWCVSS 6.8fixed in libextractor 0.5.12-1 (bookworm)2007
CVE-2007-3387 [MEDIUM] CVE-2007-3387: cups - Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, ... Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine fu
debian
CVE-2017-1000456P3HIGHCVSS 8.8fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-1000456 [HIGH] CVE-2017-1000456: poppler - freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addW... freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2019-12293P3HIGHCVSS 8.8fixed in poppler 0.71.0-5 (bookworm)2019
CVE-2019-12293 [HIGH] CVE-2019-12293: poppler - In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::... In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. Scope: local bookworm: resolved (fixed in 0.71.0-5) bullseye: resolved (fixed in 0.71.0-5) forky: resolved (fixed in 0.71.0-5) sid: resolved (fixed in 0.71.0-5) trixie: resolved (fixed in 0.71.0-5)
debian
CVE-2019-9631P3CRITICALCVSS 9.8fixed in poppler 0.71.0-4 (bookworm)2019
CVE-2019-9631 [CRITICAL] CVE-2019-9631: poppler - Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downs... Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. Scope: local bookworm: resolved (fixed in 0.71.0-4) bullseye: resolved (fixed in 0.71.0-4) forky: resolved (fixed in 0.71.0-4) sid: resolved (fixed in 0.71.0-4) trixie: resolved (fixed in 0.71.0-4)
debian
CVE-2010-4654P3HIGHCVSS 7.8fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-4654 [HIGH] CVE-2010-4654: poppler - poppler before 0.16.3 has malformed commands that may cause corruption of the in... poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2022-38784P3HIGHCVSS 7.8fixed in poppler 22.08.0-2.1 (bookworm)2022
CVE-2022-38784 [HIGH] CVE-2022-38784: poppler - Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2... Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf. Scope: local bookworm: resolved (fixed
debian
CVE-2019-10872P3LOWCVSS 8.8fixed in poppler 0.71.0-5 (bookworm)2019
CVE-2019-10872 [HIGH] CVE-2019-10872: poppler - An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-rea... An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. Scope: local bookworm: resolved (fixed in 0.71.0-5) bullseye: resolved (fixed in 0.71.0-5) forky: resolved (fixed in 0.71.0-5) sid: resolved (fixed in 0.71.0-5) trixie: resolved (fixed in 0.71.0-5)
debian
CVE-2017-15565P3HIGHCVSS 8.8fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-15565 [HIGH] CVE-2017-15565: poppler - In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::ge... In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2020-27778P3HIGHCVSS 7.5fixed in poppler 0.85.0-2 (bookworm)2020
CVE-2020-27778 [HIGH] CVE-2020-27778: poppler - A flaw was found in Poppler in the way certain PDF files were converted into HTM... A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service. Scope: local bookworm: resolved (fixed in 0.85.0-2) bullseye: resolved (fixed in 0.85.0-2) forky: resol
debian
CVE-2024-6239P3LOWCVSS 7.5fixed in poppler 24.08.0-2 (forky)2024
CVE-2024-6239 [HIGH] CVE-2024-6239: poppler - A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using ... A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 24.08.0-2) sid: resolved (fixed in 24.08.0-2) trixie: resolved (
debian
CVE-2005-3192P3LOWCVSS 7.5fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3192 [HIGH] CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used... Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. Scope: local bookworm: resolved (fixed i
debian
CVE-2009-1179P3MEDIUMCVSS 6.8fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1179 [MEDIUM] CVE-2009-1179: poppler - Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 an... Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed in 0.10.6-1)
debian
CVE-2009-0800P3MEDIUMCVSS 6.8fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0800 [MEDIUM] CVE-2009-0800: poppler - Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earli... Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fix
debian
CVE-2008-1693P3MEDIUMCVSS 6.8fixed in poppler 0.6.4-1 (bookworm)2008
CVE-2008-1693 [MEDIUM] CVE-2008-1693: poppler - The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before... The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this
debian
CVE-2017-14976P3LOWCVSS 7.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14976 [HIGH] CVE-2017-14976: poppler - The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a... The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-
debian
CVE-2019-7310P4HIGHCVSS 7.8fixed in poppler 0.71.0-4 (bookworm)2019
CVE-2019-7310 [HIGH] CVE-2019-7310: poppler - In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness e... In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo. Scope: local bookworm: resolved (fixed in 0.71.0-4) bullseye: resolv
debian
CVE-2019-14494P4HIGHCVSS 7.5fixed in poppler 0.85.0-2 (bookworm)2019
CVE-2019-14494 [HIGH] CVE-2019-14494: poppler - An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero err... An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. Scope: local bookworm: resolved (fixed in 0.85.0-2) bullseye: resolved (fixed in 0.85.0-2) forky: resolved (fixed in 0.85.0-2) sid: resolved (fixed in 0.85.0-2) trixie: resolved (fixed in 0.85.0-2)
debian
CVE-2017-14975P4LOWCVSS 7.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14975 [HIGH] CVE-2017-14975: poppler - The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a... The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved
debian
CVE-2017-14977P4LOWCVSS 7.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14977 [HIGH] CVE-2017-14977: poppler - The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has ... The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolv
debian
Debian Poppler vulnerabilities | cvebase