cbcvebase.

Debian Poppler vulnerabilities

128 known vulnerabilities affecting debian/poppler.

Total CVEs
128
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH22MEDIUM44LOW57

Vulnerabilities

Page 7 of 7
CVE-2017-14926P4LOWCVSS 5.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14926 [MEDIUM] CVE-2017-14926: poppler - In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content:... In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2017-14928P4LOWCVSS 5.5fixed in poppler 0.61.1-2 (bookworm)2017
CVE-2017-14928 [MEDIUM] CVE-2017-14928: poppler - In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configur... In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.61.1-2) bullseye: resolved (fixed in 0.61.1-2) forky: resolved (fixed in 0.61.1-2) sid: resolved (fixed in 0.61.1-2) trixie: resolved (fixed in 0.61.1-2)
debian
CVE-2010-3703P4MEDIUMCVSS 4.3fixed in poppler 0.12.4-1.2 (bookworm)2010
CVE-2010-3703 [MEDIUM] CVE-2010-3703: poppler - The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in th... The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference. Scope: local bookworm: resolved (fixed in 0.12.4
debian
CVE-2025-32364P4MEDIUMCVSS 4.0fixed in poppler 22.12.0-2+deb12u1 (bookworm)2025
CVE-2025-32364 [MEDIUM] CVE-2025-32364: poppler - A floating-point exception in the PSStack::roll function of Poppler before 25.04... A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. Scope: local bookworm: resolved (fixed in 22.12.0-2+deb12u1) bullseye: resolved (fixed in 20.09.0-3.1+deb11u2) forky: resolved (fixed in 25.03.0-3) sid: resolved (fixed in 25.03.0-3) trixie: re
debian
CVE-2010-0207P4LOWCVSS 5.5fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-0207 [MEDIUM] CVE-2010-0207: poppler - In xpdf, the xref table contains an infinite loop which allows remote attackers ... In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2025-43903P4MEDIUMCVSS 4.3fixed in poppler 25.03.0-4 (forky)2025
CVE-2025-43903 [MEDIUM] CVE-2025-43903: poppler - NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7... NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 25.03.0-4) sid: resolved (fixed in 25.03.0-4) trixie: resolved (fixed in 25.03.0-4)
debian
CVE-2025-43718P4LOWCVSS 2.9fixed in poppler 25.03.0-10 (forky)2025
CVE-2025-43718 [LOW] CVE-2025-43718: poppler - Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSE... Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::_
debian
CVE-2005-2097P4LOWCVSS 2.1fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-2097 [LOW] CVE-2005-2097: cups - xpdf and kpdf do not properly validate the "loca" table in PDF files, which allo... xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed
debian
Debian Poppler vulnerabilities | cvebase