cbcvebase.

Debian Xpdf vulnerabilities

59 known vulnerabilities affecting debian/xpdf.

Total CVEs
59
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH11MEDIUM22LOW19

Vulnerabilities

Page 3 of 3
CVE-2005-3191P4LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3191 [MEDIUM] CVE-2005-3191: cups - Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF an... Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial
debian
CVE-2005-0206P4CRITICALCVSS 10.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-0206 [CRITICAL] CVE-2005-0206: cups - The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-088... The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) si
debian
CVE-2011-1553P4LOWCVSS 6.8fixed in xpdf 3.02-9 (bookworm)2011
CVE-2011-1553 [MEDIUM] CVE-2011-1553: poppler - Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before ... Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764. Scope: local bookworm: resolved bullseye:
debian
CVE-2011-1552P4LOWCVSS 6.8fixed in xpdf 3.02-9 (bookworm)2011
CVE-2011-1552 [MEDIUM] CVE-2011-1552: poppler - t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other produc... t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resol
debian
CVE-2002-1384P4HIGHCVSS 7.2fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1384 [HIGH] CVE-2002-1384: cups - Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS ... Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf. Scope: local bookworm: resolved (fixed in 1.1.18-1) bullseye: resolved (fixed in 1.1.18-1) forky: resolved (fixed in 1.1.18-1) sid: resolved (fixed
debian
CVE-2009-3609P4MEDIUMCVSS 4.3fixed in poppler 0.12.2-1 (bookworm)2009
CVE-2009-3609 [MEDIUM] CVE-2009-3609: poppler - Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf b... Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read. Scope: local bookworm: resolved
debian
CVE-2009-0799P4MEDIUMCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0799 [MEDIUM] CVE-2009-0799: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: re
debian
CVE-2011-1554P4LOWCVSS 6.8fixed in xpdf 3.02-9 (bookworm)2011
CVE-2011-1554 [MEDIUM] CVE-2011-1554: poppler - Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teT... Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764. Scop
debian
CVE-2009-1183P4MEDIUMCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1183 [MEDIUM] CVE-2009-1183: poppler - The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppl... The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) sid: resolved (fixed i
debian
CVE-2009-1181P4MEDIUMCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-1181 [MEDIUM] CVE-2009-1181: poppler - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 0.10.6-1) bullseye: resolved (fixed in 0.10.6-1) forky: resolved (fixed in 0.10.6-1) si
debian
CVE-2009-0146P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0146 [MEDIUM] CVE-2009-0146: cups - Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS... Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixi
debian
CVE-2010-0206P4LOWCVSS 5.5fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-0206 [MEDIUM] CVE-2010-0206: poppler - xpdf allows remote attackers to cause a denial of service (NULL pointer derefere... xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2005-3624P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3624 [MEDIUM] CVE-2005-3624: cups - The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, p... The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1
debian
CVE-2009-0147P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0147 [MEDIUM] CVE-2009-0147: cups - Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUP... Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap. Scope: local bookworm: resolved bullseye: re
debian
CVE-2009-0166P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0166 [MEDIUM] CVE-2009-0166: cups - The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other... The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2005-3626P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3626 [MEDIUM] CVE-2005-3626: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l... Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1.1.22-7) forky: resolved (fixed in 1.1.22-7) sid: resolved (fix
debian
CVE-2010-3703P4MEDIUMCVSS 4.3fixed in poppler 0.12.4-1.2 (bookworm)2010
CVE-2010-3703 [MEDIUM] CVE-2010-3703: poppler - The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in th... The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference. Scope: local bookworm: resolved (fixed in 0.12.4
debian
CVE-2010-0207P4LOWCVSS 5.5fixed in poppler 0.16.3-1 (bookworm)2010
CVE-2010-0207 [MEDIUM] CVE-2010-0207: poppler - In xpdf, the xref table contains an infinite loop which allows remote attackers ... In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers. Scope: local bookworm: resolved (fixed in 0.16.3-1) bullseye: resolved (fixed in 0.16.3-1) forky: resolved (fixed in 0.16.3-1) sid: resolved (fixed in 0.16.3-1) trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2005-2097P4LOWCVSS 2.1fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-2097 [LOW] CVE-2005-2097: cups - xpdf and kpdf do not properly validate the "loca" table in PDF files, which allo... xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed
debian
Debian Xpdf vulnerabilities | cvebase