Debian Poppler vulnerabilities
128 known vulnerabilities affecting debian/poppler.
Total CVEs
128
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH22MEDIUM44LOW57
Vulnerabilities
Page 4 of 7
CVE-2019-12493P4HIGHCVSS 7.1fixed in poppler 0.44.0-2 (bookworm)2019
CVE-2019-12493 [HIGH] CVE-2019-12493: poppler - A stack-based buffer over-read exists in PostScriptFunction::transform in Functi...
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.
Scope: lo
debian
CVE-2025-52886P4MEDIUMCVSS 5.5fixed in poppler 25.03.0-5 (forky)2025
CVE-2025-52886 [MEDIUM] CVE-2025-52886: poppler - Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_i...
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 25.03.0-5)
sid: resolved (fixed in
debian
CVE-2013-1790P4LOWCVSS 6.8fixed in poppler 0.18.4-6 (bookworm)2013
CVE-2013-1790 [MEDIUM] CVE-2013-1790: poppler - poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to...
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
Scope: local
bookworm: resolved (fixed in 0.18.4-6)
bullseye: resolved (fixed in 0.18.4-6)
forky: resolved (fixed in 0.18.4-6)
sid: resolved (fixed in 0.18.4-6)
t
debian
CVE-2018-16646P4LOWCVSS 6.5fixed in poppler 0.71.0-4 (bookworm)2018
CVE-2018-16646 [MEDIUM] CVE-2018-16646: poppler - In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite...
In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
Scope: local
bookworm: resolved (fixed in 0.71.0-4)
bullseye: resolved (fixed in 0.71.0-4)
forky: resolved (fixed in 0.71.0-4)
sid: resolved (fixed in 0.71.0-4)
trixie: resolved (fixed in 0.71.0-4)
debian
CVE-2010-4653P4LOWCVSS 6.5fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-4653 [MEDIUM] CVE-2010-4653: poppler - An integer overflow condition in poppler before 0.16.3 can occur when parsing Ch...
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
Scope: local
bookworm: resolved (fixed in 0.16.3-1)
bullseye: resolved (fixed in 0.16.3-1)
forky: resolved (fixed in 0.16.3-1)
sid: resolved (fixed in 0.16.3-1)
trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2005-3625P4CRITICALCVSS 10.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3625 [CRITICAL] CVE-2005-3625: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l...
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved
debian
CVE-2019-10873P4LOWCVSS 6.5fixed in poppler 0.71.0-4 (bookworm)2019
CVE-2019-10873 [MEDIUM] CVE-2019-10873: poppler - An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference i...
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
Scope: local
bookworm: resolved (fixed in 0.71.0-4)
bullseye: resolved (fixed in 0.71.0-4)
forky: resolved (fixed in 0.71.0-4)
sid: resolved (fixed in 0.71.0-4)
trixie: resolved (fixed in 0.71.0-4)
debian
CVE-2019-12360P4HIGHCVSS 7.1fixed in poppler 0.38.0-2 (bookworm)2019
CVE-2019-12360 [HIGH] CVE-2019-12360: poppler - A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTr...
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
Scope: local
bookworm: resolved (fixed in 0.38.0-2)
bullseye:
debian
CVE-2019-10871P4LOWCVSS 6.5fixed in poppler 0.85.0-2 (bookworm)2019
CVE-2019-10871 [MEDIUM] CVE-2019-10871: poppler - An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-rea...
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
Scope: local
bookworm: resolved (fixed in 0.85.0-2)
bullseye: resolved (fixed in 0.85.0-2)
forky: resolved (fixed in 0.85.0-2)
sid: resolved (fixed in 0.85.0-2)
trixie: resolved (fixed in 0.85.0-2)
debian
CVE-2019-9903P4LOWCVSS 6.5fixed in poppler 0.85.0-2 (bookworm)2019
CVE-2019-9903 [MEDIUM] CVE-2019-9903: poppler - PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leadi...
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
Scope: local
bookworm: resolved (fixed in 0.85.0-2)
bullseye: resolved (fixed in 0.85.0-2)
forky: resolved (fixed in 0.85.0-
debian
CVE-2022-37050P4MEDIUMCVSS 6.5fixed in poppler 22.08.0-2 (bookworm)2022
CVE-2022-37050 [MEDIUM] CVE-2022-37050: poppler - In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a ...
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.
Scope: local
bookworm: resolved (fixed in 22.08.0-2)
bu
debian
CVE-2005-3193P4LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3193 [MEDIUM] CVE-2005-3193: cups - Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX ...
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF f
debian
CVE-2005-3191P4LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3191 [MEDIUM] CVE-2005-3191: cups - Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF an...
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial
debian
CVE-2025-52885P4MEDIUMCVSS 6.1fixed in poppler 25.03.0-11.1 (forky)2025
CVE-2025-52885 [MEDIUM] CVE-2025-52885: poppler - Poppler ia a library for rendering PDF files, and examining or modifying their s...
Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue arises from the use of raw pointers to elements of a `std::vector`, which can lead to dangling pointers when the vector is resized. The vul
debian
CVE-2017-9775P4MEDIUMCVSS 6.5fixed in poppler 0.57.0-2 (bookworm)2017
CVE-2017-9775 [MEDIUM] CVE-2017-9775: poppler - Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows...
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
Scope: local
bookworm: resolved (fixed in 0.57.0-2)
bullseye: resolved (fixed in 0.57.0-2)
forky: resolved (fixed in 0.57.0-2)
sid: resolved (fixed in 0.57.0-2)
trixie: resolved (fixed in 0.57.
debian
CVE-2018-20481P4LOWCVSS 6.5fixed in poppler 0.71.0-4 (bookworm)2018
CVE-2018-20481 [MEDIUM] CVE-2018-20481: poppler - XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries,...
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
Scope: local
bookworm: resolved (fixed in 0.71.0-4)
bullseye: resolved (fixed in 0.71.0-4
debian
CVE-2018-10768P4MEDIUMCVSS 6.5fixed in poppler 0.38.0-2 (bookworm)2018
CVE-2018-10768 [MEDIUM] CVE-2018-10768: poppler - There is a NULL pointer dereference in the AnnotPath::getCoordsLength function i...
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
Scope: local
bookworm: resolved (fixed in 0.38.0-2)
bullseye: resolved (fixed in 0.38.0-2)
forky: resolv
debian
CVE-2018-19059P4LOWCVSS 6.5fixed in poppler 0.85.0-2 (bookworm)2018
CVE-2018-19059 [MEDIUM] CVE-2018-19059: poppler - An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbF...
An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.
Scope: local
bookworm: resolved (fixed in 0.85.0-2)
bullseye: resolved (fixed in 0.85.0-2)
forky: resolved (fixed in 0.85.0-2)
sid: resol
debian
CVE-2022-37051P4MEDIUMCVSS 6.5fixed in poppler 22.08.0-2 (bookworm)2022
CVE-2022-37051 [MEDIUM] CVE-2022-37051: poppler - An issue was discovered in Poppler 22.07.0. There is a reachable abort which lea...
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
Scope: local
bookworm: resolved (fixed in 22.08.0-2)
bullseye: resolved (fixed in 20.09.0-3.1+deb11u2)
forky: resolved (fixed in 22.08.0-2)
sid: resolved (fixed in 22.0
debian
CVE-2022-38349P4MEDIUMCVSS 6.5fixed in poppler 22.12.0-2 (bookworm)2022
CVE-2022-38349 [MEDIUM] CVE-2022-38349: poppler - An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Ob...
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
Scope: local
bookworm: resolved (fixed in 22.12.0-2)
bullseye: resolved (fixed in 20.09.0-3.1+deb11u2)
forky: resolved (fixed in 22.12.0-2)
sid: reso
debian