Debian Xpdf vulnerabilities
171 known vulnerabilities affecting debian/xpdf.
Total CVEs
171
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH11MEDIUM22LOW131
Vulnerabilities
Page 9 of 9
CVE-2005-3626MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3626 [MEDIUM] CVE-2005-3626: cups - Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, l...
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1.1.22-7)
forky: resolved (fixed in 1.1.22-7)
sid: resolved (fix
debian
CVE-2005-3624MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3624 [MEDIUM] CVE-2005-3624: cups - The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, p...
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed in 1
debian
CVE-2005-3192LOWCVSS 7.5fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3192 [HIGH] CVE-2005-3192: cups - Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used...
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
Scope: local
bookworm: resolved (fixed i
debian
CVE-2005-2097LOWCVSS 2.1fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-2097 [LOW] CVE-2005-2097: cups - xpdf and kpdf do not properly validate the "loca" table in PDF files, which allo...
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
Scope: local
bookworm: resolved (fixed in 1.1.22-7)
bullseye: resolved (fixed
debian
CVE-2005-3193LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3193 [MEDIUM] CVE-2005-3193: cups - Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX ...
Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF f
debian
CVE-2005-3191LOWCVSS 5.1fixed in cups 1.1.23-13 (bookworm)2005
CVE-2005-3191 [MEDIUM] CVE-2005-3191: cups - Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF an...
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial
debian
CVE-2004-0888CRITICALCVSS 10.0fixed in cups 1.1.22-6 (bookworm)2004
CVE-2004-0888 [CRITICAL] CVE-2004-0888: cups - Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf...
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
Scope: local
bookworm: resolved (fixed in 1.1.22-6)
bullseye: resolved (fi
debian
CVE-2004-1125CRITICALCVSS 9.3fixed in cups 1.1.22-2 (bookworm)2004
CVE-2004-1125 [CRITICAL] CVE-2004-1125: cups - Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other ...
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded
debian
CVE-2004-0889MEDIUMCVSS 10.0fixed in xpdf 3.00-10 (bookworm)2004
CVE-2004-0889 [CRITICAL] CVE-2004-0889: xpdf - Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code su...
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
Scope: local
bookworm: resolved (fixed in 3.00-10)
bullseye: resolved (fixed in 3.00-10)
forky: resolved
debian
CVE-2003-0434HIGHCVSS 7.5PoCfixed in xpdf 2.02pl1-1 (bookworm)2003
CVE-2003-0434 [HIGH] CVE-2003-0434: xpdf - Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow rem...
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Scope: local
bookworm: resolved (fixed in 2.02pl1-1)
bullseye: resolved (fixed in 2.02pl1-1)
forky: resolved (fixed in 2.02pl1-1)
sid: resolved (fixed in 2.02pl1-1)
trixie: resolved (fixed in 2.02pl
debian
CVE-2002-1384HIGHCVSS 7.2fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1384 [HIGH] CVE-2002-1384: cups - Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS ...
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
Scope: local
bookworm: resolved (fixed in 1.1.18-1)
bullseye: resolved (fixed in 1.1.18-1)
forky: resolved (fixed in 1.1.18-1)
sid: resolved (fixed
debian
← Previous9 / 9