Freedesktop Poppler vulnerabilities

157 known vulnerabilities affecting freedesktop/poppler.

Total CVEs
157
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH52MEDIUM92LOW4

Vulnerabilities

Page 3 of 8
CVE-2019-12957HIGHCVSS 7.8≥ 0, < 0.22.5-42019-06-25
CVE-2019-12957 [HIGH] CVE-2019-12957: In Xpdf 4 In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
osv
CVE-2019-12958MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.6≥ 0, < 0.57.0-2ubuntu42019-06-25
CVE-2019-12958 [MEDIUM] CVE-2019-12958: In Xpdf 4 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.
osv
CVE-2019-12515HIGHCVSS 7.1≥ 0, < 0.41.0-0ubuntu1.13≥ 0, < 0.62.0-2ubuntu2.82019-06-02
CVE-2019-12515 [HIGH] CVE-2019-12515: There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service.
osv
CVE-2019-12493HIGHCVSS 7.1≥ 0, < 0.44.0-22019-05-31
CVE-2019-12493 [HIGH] CVE-2019-12493: A stack-based buffer over-read exists in PostScriptFunction::transform in Function A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.
osv
CVE-2019-12360HIGHCVSS 7.1≥ 0, < 0.38.0-22019-05-27
CVE-2019-12360 [HIGH] CVE-2019-12360: A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
osv
CVE-2019-12293HIGHCVSS 8.8≤ 0.76.12019-05-23
CVE-2019-12293 [HIGH] CWE-125 CVE-2019-12293: In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stre In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.
nvdosv
CVE-2019-11026MEDIUMCVSS 6.5v0.75.02019-04-08
CVE-2019-11026 [MEDIUM] CWE-674 CVE-2019-11026: FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a cal FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
nvdosv
CVE-2019-10872HIGHCVSS 8.8v0.74.02019-04-05
CVE-2019-10872 [HIGH] CWE-125 CVE-2019-10872: An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Sp An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
nvdosv
CVE-2019-10871MEDIUMCVSS 6.5v0.74.02019-04-05
CVE-2019-10871 [MEDIUM] CWE-125 CVE-2019-10871: An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PS An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
nvdosv
CVE-2019-10873MEDIUMCVSS 6.5v0.74.02019-04-05
CVE-2019-10873 [MEDIUM] CWE-476 CVE-2019-10873: An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function Splas An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
nvdosv
CVE-2019-10026MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.13≥ 0, < 0.62.0-2ubuntu2.82019-03-25
CVE-2019-10026 [MEDIUM] CVE-2019-10026: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.
osv
CVE-2019-10020MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.42019-03-25
CVE-2019-10020 [MEDIUM] CVE-2019-10020: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.
osv
CVE-2019-10022MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.13≥ 0, < 0.62.0-2ubuntu2.82019-03-25
CVE-2019-10022 [MEDIUM] CVE-2019-10022: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.
osv
CVE-2019-10025MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.13≥ 0, < 0.62.0-2ubuntu2.82019-03-25
CVE-2019-10025 [MEDIUM] CVE-2019-10025: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.
osv
CVE-2019-10024MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.42019-03-25
CVE-2019-10024 [MEDIUM] CVE-2019-10024: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.
osv
CVE-2019-10018MEDIUMCVSS 5.5≥ 0, < 0.57.0-22019-03-25
CVE-2019-10018 [MEDIUM] CVE-2019-10018: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.
osv
CVE-2019-10021MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.142019-03-24
CVE-2019-10021 [MEDIUM] CVE-2019-10021: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps.
osv
CVE-2019-10023MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.142019-03-24
CVE-2019-10023 [MEDIUM] CVE-2019-10023: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.
osv
CVE-2019-10019MEDIUMCVSS 5.5≥ 0, < 0.41.0-0ubuntu1.142019-03-24
CVE-2019-10019 [MEDIUM] CVE-2019-10019: An issue was discovered in Xpdf 4 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes.
osv
CVE-2019-9877HIGHCVSS 7.8≥ 0, < 0.41.0-0ubuntu1.13≥ 0, < 0.62.0-2ubuntu2.82019-03-21
CVE-2019-9877 [HIGH] CVE-2019-9877: There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
osv