cbcvebase.

Debian Poppler vulnerabilities

128 known vulnerabilities affecting debian/poppler.

Total CVEs
128
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH22MEDIUM44LOW57

Vulnerabilities

Page 6 of 7
CVE-2009-0799P4MEDIUMCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0799 [MEDIUM] CVE-2009-0799: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: re
debian
CVE-2011-1554P4LOWCVSS 6.8fixed in xpdf 3.02-9 (bookworm)2011
CVE-2011-1554 [MEDIUM] CVE-2011-1554: poppler - Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teT... Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764. Scop
debian
CVE-2009-1183P4MEDIUMCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1183 [MEDIUM] CVE-2009-1183: poppler - The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppl... The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed i
debian
CVE-2010-5110P4MEDIUMCVSS 4.3fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-5110 [MEDIUM] CVE-2010-5110: poppler - DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial ... DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2024-56378P4MEDIUMCVSS 4.3fixed in poppler 22.12.0-2+deb12u1 (bookworm)2024
CVE-2024-56378 [MEDIUM] CVE-2024-56378: poppler - libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability... libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc. Scope: local bookworm: resolved (fixed in 22.12.0-2+deb12u1) bullseye: resolved (fixed in 20.09.0-3.1+deb11u2) forky: resolved (fixed in 24.08.0-4) sid: resolved (fixed in 24.08.0-4) trixie: resolved (fixed in 24.08.0-4)
debian
CVE-2017-18267P4MEDIUMCVSS 5.5fixed in poppler 0.69.0-2 (bookworm)2017
CVE-2017-18267 [MEDIUM] CVE-2017-18267: poppler - The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.... The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops. Scope: local bookworm: resolved (fixed in 0.69.0-2) bullseye: resolved (fixed in 0.69.0-2) forky: resolved (fixed in 0.69.0-2) sid: resolved (fixed in 0.69.0-
debian
CVE-2017-7511P4LOWCVSS 5.5fixed in poppler 0.57.0-2 (bookworm)2017
CVE-2017-7511 [MEDIUM] CVE-2017-7511: poppler - poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in ... poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents. Scope: local bookworm: resolved (fixed in 0.57.0-2) bullseye: resolved (fixed in 0.57.0-2) forky: resolved (fixed in 0.57.0-2) sid: resolved (fixed in 0.57.0-2) trixie: resolved (fixed in 0.57.0-2)
debian
CVE-2009-1181P4MEDIUMCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1181 [MEDIUM] CVE-2009-1181: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) si
debian
CVE-2020-36024P4MEDIUMCVSS 5.5fixed in poppler 22.08.0-2 (bookworm)2020
CVE-2020-36024 [MEDIUM] CVE-2020-36024: poppler - An issue was discovered in freedesktop poppler version 20.12.1, allows remote at... An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function. Scope: local bookworm: resolved (fixed in 22.08.0-2) bullseye: resolved (fixed in 20.09.0-3.1+deb11u2) forky: resolved (fixed in 22.08.0-2) sid: resolved (fixed in 22.08.0-2) trixie
debian
CVE-2009-0146P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0146 [MEDIUM] CVE-2009-0146: cups - Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS... Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixi
debian
CVE-2019-10018P4LOWCVSS 5.5fixed in poppler 0.57.0-2 (bookworm)2019
CVE-2019-10018 [MEDIUM] CVE-2019-10018: poppler - An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScr... An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case. Scope: local bookworm: resolved (fixed in 0.57.0-2) bullseye: resolved (fixed in 0.57.0-2) forky: resolved (fixed in 0.57.0-2) sid: resolved (fixed in 0.57.0-2) trixie: resolved (fixed in 0.57.0-2)
debian
CVE-2010-0206P4LOWCVSS 5.5fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-0206 [MEDIUM] CVE-2010-0206: poppler - xpdf allows remote attackers to cause a denial of service (NULL pointer derefere... xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2005-3624P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3624 [MEDIUM] CVE-2005-3624: cups - The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, p... The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1
debian
CVE-2009-0147P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0147 [MEDIUM] CVE-2009-0147: cups - Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUP... Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap. Scope: local bookworm: resolved bullseye: re
debian
CVE-2009-0166P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0166 [MEDIUM] CVE-2009-0166: cups - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2005-3626P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3626 [MEDIUM] CVE-2005-3626: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l... Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fix
debian
CVE-2017-7515P4LOWCVSS 5.5fixed in poppler 0.57.0-2 (bookworm)2017
CVE-2017-7515 [MEDIUM] CVE-2017-7515: poppler - poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdf... poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service. Scope: local bookworm: resolved (fixed in 0.57.0-2) bullseye: resolved (fixed in 0.57.0-2) forky: resolved (fixed in 0.57.0-2) sid: resolved (fixed in 0.57.0-2) trixie: resolved (fixed in 0.57.0-2)
debian
CVE-2017-14517P4LOWCVSS 5.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14517 [MEDIUM] CVE-2017-14517: poppler - In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() f... In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2023-34872P4MEDIUMCVSS 5.5fixed in poppler 22.12.0-2+deb12u1 (bookworm)2023
CVE-2023-34872 [MEDIUM] CVE-2023-34872: poppler - A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attac... A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open. Scope: local bookworm: resolved (fixed in 22.12.0-2+deb12u1) bullseye: resolved forky: resolved (fixed in 24.02.0-2) sid: resolved (fixed in 24.02.0-2) trixie: resolved (fixed in 24.02.0-2)
debian
CVE-2017-14927P4LOWCVSS 5.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14927 [MEDIUM] CVE-2017-14927: poppler - In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::typ... In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
Debian Poppler vulnerabilities | cvebase