Gnome Evince vulnerabilities
13 known vulnerabilities affecting gnome/evince.
Total CVEs
13
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH10MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-51698HIGHCVSS 8.8≥ 0, < 3.25.92-12024-01-12
CVE-2023-51698 [HIGH] CVE-2023-51698: Atril is a simple multi-page document viewer
Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available at commit ce41df6.
osv
CVE-2013-3718MEDIUMCVSS 5.5v3.8.2v3.9.22019-11-01
CVE-2013-3718 [MEDIUM] CWE-20 CVE-2013-3718: evince is missing a check on number of pages which can lead to a segmentation fault
evince is missing a check on number of pages which can lead to a segmentation fault
nvdosv
CVE-2019-1010006HIGHCVSS 7.8v3.26.02019-07-15
CVE-2019-1010006 [HIGH] CWE-190 CVE-2019-1010006: Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The comp
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.
nvdosv
CVE-2019-11459MEDIUMCVSS 5.5≤ 3.32.02019-04-22
CVE-2019-11459 [MEDIUM] CWE-754 CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
nvdosv
CVE-2017-1000159HIGHCVSS 7.8fixed in 3.25.912017-11-27
CVE-2017-1000159 [HIGH] CWE-78 CVE-2017-1000159: Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
nvdosv
CVE-2017-1000083HIGHCVSS 7.8PoC≤ 3.24.02017-09-05
CVE-2017-1000083 [HIGH] CVE-2017-1000083: backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows r
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
nvdosv
CVE-2011-0433HIGHCVSS 7.6≥ 0, < 2.32.0-12012-11-19
CVE-2011-0433 [HIGH] CVE-2011-0433: Heap-based buffer overflow in the linetoken function in afmparse
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.
osv
CVE-2011-5244HIGHCVSS 7.6≥ 0, < 2.32.0-12012-11-19
CVE-2011-5244 [HIGH] CVE-2011-5244: Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse
Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vu
osv
CVE-2010-2642HIGHCVSS 7.6≥ 0, < 3.0.2-12011-01-07
CVE-2010-2642 [HIGH] CVE-2010-2642: Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
osv
CVE-2010-2643HIGHCVSS 7.6≥ 0, < 2.30.3-22011-01-07
CVE-2010-2643 [HIGH] CVE-2010-2643: Integer overflow in the TFM font parser in the dvi-backend component in Evince 2
Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
osv
CVE-2010-2641HIGHCVSS 7.6≥ 0, < 2.30.3-22011-01-07
CVE-2010-2641 [HIGH] CVE-2010-2641: Array index error in the VF font parser in the dvi-backend component in Evince 2
Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
osv
CVE-2010-2640HIGHCVSS 7.6≥ 0, < 2.30.3-22011-01-07
CVE-2010-2640 [HIGH] CVE-2010-2640: Array index error in the PK font parser in the dvi-backend component in Evince 2
Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
osv
CVE-2006-5864MEDIUMCVSS 5.1PoC≥ 0, < 0.4.0-32006-11-11
CVE-2006-5864 [MEDIUM] CVE-2006-5864: Stack-based buffer overflow in the ps_gettext function in ps
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited
osv