cbcvebase.

Debian Poppler vulnerabilities

128 known vulnerabilities affecting debian/poppler.

Total CVEs
128
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH22MEDIUM44LOW57

Vulnerabilities

Page 3 of 7
CVE-2020-23804P4HIGHCVSS 7.5fixed in poppler 20.09.0-1 (bookworm)2020
CVE-2020-23804 [HIGH] CVE-2020-23804: poppler - Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote a... Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input. Scope: local bookworm: resolved (fixed in 20.09.0-1) bullseye: resolved (fixed in 20.09.0-1) forky: resolved (fixed in 20.09.0-1) sid: resolved (fixed in 20.09.0-1) trixie: resolved (fixed in 20.09.0-1)
debian
CVE-2005-3627P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3627 [HIGH] CVE-2005-3627: cups - Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, t... Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index
debian
CVE-2006-0301P4MEDIUMCVSS 7.5fixed in libextractor 0.5.10-1 (bookworm)2006
CVE-2006-0301 [HIGH] CVE-2006-0301: libextractor - Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such ... Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap. Scope: local b
debian
CVE-2019-12957P4HIGHCVSS 7.8fixed in poppler 0.22.5-4 (bookworm)2019
CVE-2019-12957 [HIGH] CVE-2019-12957: poppler - In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToT... In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibl
debian
CVE-2017-14519P4HIGHCVSS 7.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14519 [HIGH] CVE-2017-14519: poppler - In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar i... In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop). Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved
debian
CVE-2017-14929P4HIGHCVSS 7.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14929 [HIGH] CVE-2017-14929: poppler - In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in... In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519. Scope: local bookworm: resolved (fixed in 0.61.1-2) bul
debian
CVE-2017-14520P4LOWCVSS 7.8fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14520 [HIGH] CVE-2017-14520: poppler - In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd()... In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2017-14518P4LOWCVSS 7.8fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14518 [HIGH] CVE-2017-14518: poppler - In Poppler 0.59.0, a floating point exception exists in the isImageInterpolation... In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2010-3704P4MEDIUMCVSS 6.8fixed in poppler 0.12.4-1.2 (bookworm)2010
CVE-2010-3704 [MEDIUM] CVE-2010-3704: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf bef... The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a ne
debian
CVE-2009-1188P4MEDIUMCVSS 5.0fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1188 [MEDIUM] CVE-2009-1188: poppler - Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap... Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document. Scope: local bookworm: resolved (fixed i
debian
CVE-2009-3938P4LOWCVSS 6.8fixed in poppler 0.12.2-2.1 (bookworm)2009
CVE-2009-3938 [MEDIUM] CVE-2009-3938: poppler - Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc... Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.12
debian
CVE-2010-3702P4HIGHCVSS 7.5fixed in poppler 0.12.4-1.2 (bookworm)2010
CVE-2010-3702 [HIGH] CVE-2010-3702: poppler - The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7... The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference. Scope: local bookworm: resolved (fixed in 0.12.4-1.2) bul
debian
CVE-2017-9776P4HIGHCVSS 7.8fixed in poppler 0.57.0-2 (bookworm)2017
CVE-2017-9776 [HIGH] CVE-2017-9776: poppler - Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo... Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.57.0-2) bullseye: resolved (fixed in 0.57.0-2) forky: resolved (fixed in 0.57.0
debian
CVE-2013-1788P4LOWCVSS 6.8fixed in poppler 0.18.4-6 (bookworm)2013
CVE-2013-1788 [MEDIUM] CVE-2013-1788: poppler - poppler before 0.22.1 allows context-dependent attackers to cause a denial of se... poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc. Scope: local bookworm: resolved (fixed in 0.18.4-6) bullseye: resolved (fixed in 0.18.4-6) forky: resolved (f
debian
CVE-2017-14617P4HIGHCVSS 7.8fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14617 [HIGH] CVE-2017-14617: poppler - In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in... In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2009-1187P4MEDIUMCVSS 5.0fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1187 [MEDIUM] CVE-2009-1187: poppler - Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows r... Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc). Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved
debian
CVE-2018-13988P4LOWCVSS 6.5fixed in poppler 0.69.0-2 (bookworm)2018
CVE-2018-13988 [MEDIUM] CVE-2018-13988: poppler - Poppler through 0.62 contains an out of bounds read vulnerability due to an inco... Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file. Scope: local bookworm: resolved (fixed in 0.69.0-2) bullseye: r
debian
CVE-2019-9959P4LOWCVSS 6.5fixed in poppler 0.85.0-2 (bookworm)2019
CVE-2019-9959 [MEDIUM] CVE-2019-9959: poppler - The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for neg... The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo. Scope: local bookworm: resolved (fixed in 0.85.0-2) bullseye: resolved (fixed in 0
debian
CVE-2007-0104P4LOWCVSS 6.8fixed in poppler 0.4.5-5.1 (bookworm)2007
CVE-2007-0104 [MEDIUM] CVE-2007-0104: poppler - The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) k... The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a cr
debian
CVE-2009-3605P4MEDIUMCVSS 6.8fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3605 [MEDIUM] CVE-2009-3605: poppler - Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers ... Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/;
debian
Debian Poppler vulnerabilities | cvebase