cbcvebase.

Debian Xpdf vulnerabilities

59 known vulnerabilities affecting debian/xpdf.

Total CVEs
59
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH11MEDIUM22LOW19

Vulnerabilities

Page 1 of 3
CVE-2003-0434P3HIGHCVSS 7.5PoCfixed in xpdf 2.02pl1-1 (bookworm)2003
CVE-2003-0434 [HIGH] CVE-2003-0434: xpdf - Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow rem... Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. Scope: local bookworm: resolved (fixed in 2.02pl1-1) bullseye: resolved (fixed in 2.02pl1-1) forky: resolved (fixed in 2.02pl1-1) sid: resolved (fixed in 2.02pl1-1) trixie: resolved (fixed in 2.02pl
debian
CVE-2008-2950P3MEDIUMCVSS 7.5PoCfixed in poppler 0.8.4-1.1 (bookworm)2008
CVE-2008-2950 [HIGH] CVE-2008-2950: poppler - The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier delete... The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document. Scope: local bookworm: resolved (fixed in 0.8.4-1.1) bullseye: resolved (fixed in 0.8.4-1.1) forky: resolved (fixed in 0.8.4-1.1)
debian
CVE-2009-3608P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3608 [CRITICAL] CVE-2009-3608: poppler - Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3... Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.12.2-1) bul
debian
CVE-2009-3606P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3606 [CRITICAL] CVE-2009-3606: poppler - Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl... Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 0.12.2-1) bullseye: resolved (fixed in 0.12.2-1) forky: resolved (fix
debian
CVE-2011-0764P3LOWCVSS 6.8fixed in xpdf 3.02-9 (bookworm)2011
CVE-2011-0764 [MEDIUM] CVE-2011-0764: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc... t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: r
debian
CVE-2009-1182P3MEDIUMCVSS 7.5fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1182 [HIGH] CVE-2009-1182: poppler - Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, ... Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed in
debian
CVE-2009-3604P3MEDIUMCVSS 9.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3604 [CRITICAL] CVE-2009-3604: poppler - The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, ... The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-base
debian
CVE-2007-5392P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5392 [CRITICAL] CVE-2007-5392: cups - Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p1... Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fixed in 1.1.22-7) trixie: r
debian
CVE-2012-2142P3LOWCVSS 7.8fixed in poppler 0.18.4-7 (bookworm)2012
CVE-2012-2142 [HIGH] CVE-2012-2142: poppler - The error function in Error.cc in poppler before 0.21.4 allows remote attackers ... The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. Scope: local bookworm: resolved (fixed in 0.18.4-7) bullseye: resolved (fixed in 0.18.4-7) forky: resolved (fixed in 0.18.4-7) sid: resolved (fixed in 0.18.4-7) trixie: resolved (fixed in 0.18.4-
debian
CVE-2009-3603P3MEDIUMCVSS 5.0fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3603 [MEDIUM] CVE-2009-3603: poppler - Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3... Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplet
debian
CVE-2009-4035P3CRITICALCVSS 9.3fixed in poppler 0.5.1-1 (bookworm)2009
CVE-2009-4035 [CRITICAL] CVE-2009-4035: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kp... The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a
debian
CVE-2007-5393P3CRITICALCVSS 9.3fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-5393 [CRITICAL] CVE-2007-5393: cups - Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream... Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fixed in 1.1.22
debian
CVE-2007-4352P3HIGHCVSS 7.6fixed in cups 1.1.22-7 (bookworm)2007
CVE-2007-4352 [HIGH] CVE-2007-4352: cups - Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Strea... Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: re
debian
CVE-2009-1180P3MEDIUMCVSS 6.8fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1180 [MEDIUM] CVE-2009-1180: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fi
debian
CVE-2007-3387P3LOWCVSS 6.8fixed in libextractor 0.5.12-1 (bookworm)2007
CVE-2007-3387 [MEDIUM] CVE-2007-3387: cups - Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, ... Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine fu
debian
CVE-2010-4654P3HIGHCVSS 7.8fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-4654 [HIGH] CVE-2010-4654: poppler - poppler before 0.16.3 has malformed commands that may cause corruption of the in... poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2009-0165P3LOWCVSS 10.0fixed in xpdf 3.02-1.4+lenny1 (bookworm)2009
CVE-2009-0165 [CRITICAL] CVE-2009-0165: xpdf - Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Po... Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn." Scope: local bookworm: resolved (fixed in 3.02-1.4+lenny1) bullseye: resolved (fixed in 3.02-1.4+lenny1) forky: resolved (fixed in 3.02-1.4+lenny1) sid: resolved (fixed in 3.02-1.4+lenny1) t
debian
CVE-2005-3192P3LOWCVSS 7.5fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3192 [HIGH] CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used... Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. Scope: local bookworm: resolved (fixed i
debian
CVE-2009-1179P3MEDIUMCVSS 6.8fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1179 [MEDIUM] CVE-2009-1179: poppler - Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 an... Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed in 0.10.6-1)
debian
CVE-2009-0800P3MEDIUMCVSS 6.8fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0800 [MEDIUM] CVE-2009-0800: poppler - Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earli... Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fix
debian
Debian Xpdf vulnerabilities | cvebase