Debian Xpdf vulnerabilities
59 known vulnerabilities affecting debian/xpdf.
Total CVEs
59
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH11MEDIUM22LOW19
Vulnerabilities
Page 2 of 3
CVE-2004-0888P4CRITICALCVSS 10.0fixed in cups 1.1.22-6 (bookworm)2004
CVE-2004-0888 [CRITICAL] CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fi
debian
CVE-2008-1693P3MEDIUMCVSS 6.8fixed in poppler 0.6.4-1 (bookworm)2008
CVE-2008-1693 [MEDIUM] CVE-2008-1693: poppler - The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before...
The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this
debian
CVE-2009-0195P3MEDIUMCVSS 6.8fixed in xpdf 3.02-1.4+lenny1 (bookworm)2009
CVE-2009-0195 [MEDIUM] CVE-2009-0195: xpdf - Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably...
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
Scope: local
bookworm: resolved (fixed in 3.02-1.4+lenny1)
bullseye: resolved (fixed in 3.02-1.4+lenny1)
forky: resolved (fixed in 3.02-1.4+lenny1)
sid: resolved
debian
CVE-2005-0064P3HIGHCVSS 7.5fixed in cups 1.1.22-6 (bookworm)2005
CVE-2005-0064 [HIGH] CVE-2005-0064: cups - Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.0...
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fixed in 1.1.22-6)
forky: resolved (fixed in 1.1.22-6)
sid: resolved (fixed in 1.1.22-6)
trixie
debian
CVE-2005-3627P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3627 [HIGH] CVE-2005-3627: cups - Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, t...
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index
debian
CVE-2004-1125P4CRITICALCVSS 9.3fixed in cups 1.1.22-2 (bookworm)2004
CVE-2004-1125 [CRITICAL] CVE-2004-1125: cups - Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other ...
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded
debian
CVE-2006-0301P4MEDIUMCVSS 7.5fixed in libextractor 0.5.10-1 (bookworm)2006
CVE-2006-0301 [HIGH] CVE-2006-0301: libextractor - Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such ...
Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
Scope: local
b
debian
CVE-2019-12957P4HIGHCVSS 7.8fixed in poppler 0.22.5-4 (bookworm)2019
CVE-2019-12957 [HIGH] CVE-2019-12957: poppler - In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToT...
In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibl
debian
CVE-2011-2902P4LOWCVSS 5.3fixed in xpdf 3.02-19 (bookworm)2011
CVE-2011-2902 [MEDIUM] CVE-2011-2902: xpdf - zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1...
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
Scope: local
bookworm: resolved (fixed in 3.02-19)
bullseye: resolved (fixed in 3.02-19)
forky: resolved (fixed in 3.02-19)
sid: resolv
debian
CVE-2004-0889P4MEDIUMCVSS 10.0fixed in xpdf 3.00-10 (bookworm)2004
CVE-2004-0889 [CRITICAL] CVE-2004-0889: xpdf - Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code su...
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
Scope: local
bookworm: resolved (fixed in 3.00-10)
bullseye: resolved (fixed in 3.00-10)
forky: resolved
debian
CVE-2005-3628P4HIGHCVSS 7.5fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3628 [HIGH] CVE-2005-3628: cups - Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xp...
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
f
debian
CVE-2010-3704P4MEDIUMCVSS 6.8fixed in poppler 0.12.4-1.2 (bookworm)2010
CVE-2010-3704 [MEDIUM] CVE-2010-3704: poppler - The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf bef...
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a ne
debian
CVE-2009-1188P4MEDIUMCVSS 5.0fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1188 [MEDIUM] CVE-2009-1188: poppler - Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap...
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2010-3702P4HIGHCVSS 7.5fixed in poppler 0.12.4-1.2 (bookworm)2010
CVE-2010-3702 [HIGH] CVE-2010-3702: poppler - The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7...
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.12.4-1.2)
bul
debian
CVE-2007-0104P4LOWCVSS 6.8fixed in poppler 0.4.5-5.1 (bookworm)2007
CVE-2007-0104 [MEDIUM] CVE-2007-0104: poppler - The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) k...
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a cr
debian
CVE-2019-12493P4HIGHCVSS 7.1fixed in poppler 0.44.0-2 (bookworm)2019
CVE-2019-12493 [HIGH] CVE-2019-12493: poppler - A stack-based buffer over-read exists in PostScriptFunction::transform in Functi...
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.
Scope: lo
debian
CVE-2010-4653P4LOWCVSS 6.5fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-4653 [MEDIUM] CVE-2010-4653: poppler - An integer overflow condition in poppler before 0.16.3 can occur when parsing Ch...
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
Scope: local
bookworm: resolved (fixed in 0.16.3-1)
bullseye: resolved (fixed in 0.16.3-1)
forky: resolved (fixed in 0.16.3-1)
sid: resolved (fixed in 0.16.3-1)
trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2005-3625P4CRITICALCVSS 10.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3625 [CRITICAL] CVE-2005-3625: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l...
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved
debian
CVE-2019-12360P4HIGHCVSS 7.1fixed in poppler 0.38.0-2 (bookworm)2019
CVE-2019-12360 [HIGH] CVE-2019-12360: poppler - A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTr...
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
Scope: local
bookworm: resolved (fixed in 0.38.0-2)
bullseye:
debian
CVE-2005-3193P4LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3193 [MEDIUM] CVE-2005-3193: cups - Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX ...
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF f
debian