cbcvebase.

Gnu Libextractor vulnerabilities

29 known vulnerabilities affecting gnu/libextractor.

Total CVEs
29
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH11MEDIUM14LOW1

Vulnerabilities

Page 1 of 2
CVE-2006-2458P3MEDIUMCVSS 4.0PoC≥ 0, < 0.5.14-12006-05-18
CVE-2006-2458 [MEDIUM] CVE-2006-2458: Multiple heap-based buffer overflows in Libextractor 0 Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).
osv
CVE-2018-14346P3HIGHCVSS 8.8fixed in 1.72018-07-17
CVE-2018-14346 [HIGH] CWE-787 CVE-2018-14346: GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c). GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
nvdosv
CVE-2007-5392P3CRITICALCVSS 9.3≥ 0, < 0.5.12-12007-11-08
CVE-2007-5392 [CRITICAL] CVE-2007-5392: Integer overflow in the DCTStream::reset method in xpdf/Stream Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
osv
CVE-2007-5393P3CRITICALCVSS 9.3≥ 0, < 0.5.12-12007-11-08
CVE-2007-5393 [CRITICAL] CVE-2007-5393: Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.
osv
CVE-2007-4352P3HIGHCVSS 7.6≥ 0, < 0.5.12-12007-11-08
CVE-2007-4352 [HIGH] CVE-2007-4352: Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
osv
CVE-2007-3387P3MEDIUMCVSS 6.8≥ 0, < 0.5.12-12007-07-30
CVE-2007-3387 [MEDIUM] CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3 Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
osv
CVE-2018-16430P3HIGHCVSS 8.8≤ 1.72018-09-04
CVE-2018-16430 [HIGH] CWE-125 CVE-2018-16430: GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
nvdosv
CVE-2005-3192P3HIGHCVSS 7.5≥ 0, < 0.5.8-12005-12-08
CVE-2005-3192 [HIGH] CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3 Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
osv
CVE-2017-15601P3HIGHCVSS 7.5v1.42017-10-18
CVE-2017-15601 [HIGH] CWE-119 CVE-2017-15601: In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method f In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup.
nvdosv
CVE-2017-15267P4HIGHCVSS 7.5v1.42017-10-11
CVE-2017-15267 [HIGH] CWE-476 CVE-2017-15267: In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c. In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
nvdosv
CVE-2005-3627P4HIGHCVSS 7.5≥ 0, < 0.5.9-12005-12-31
CVE-2005-3627 [HIGH] CVE-2005-3627: Stream Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of
osv
CVE-2006-0301P4HIGHCVSS 7.5≥ 0, < 0.5.10-12006-01-30
CVE-2006-0301 [HIGH] CVE-2006-0301: Heap-based buffer overflow in Splash Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.
osv
CVE-2017-15600P4HIGHCVSS 7.5v1.42017-10-18
CVE-2017-15600 [HIGH] CWE-476 CVE-2017-15600: In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method fun In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.
nvdosv
CVE-2017-15602P4HIGHCVSS 7.5v1.42017-10-18
CVE-2017-15602 [HIGH] CWE-835 CVE-2017-15602: In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_ns In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.
nvdosv
CVE-2005-3628P4HIGHCVSS 7.5≥ 0, < 0.5.9-12005-12-31
CVE-2005-3628 [HIGH] CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
osv
CVE-2005-3625P4CRITICALCVSS 10.0≥ 0, < 0.5.9-12005-12-31
CVE-2005-3625 [CRITICAL] CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
osv
CVE-2018-20430P4MEDIUMCVSS 6.5≤ 1.82018-12-24
CVE-2018-20430 [MEDIUM] CWE-125 CVE-2018-20430: GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
nvdosv
CVE-2005-3191P4MEDIUMCVSS 5.1≥ 0, < 0.5.8-12005-12-07
CVE-2005-3191 [MEDIUM] CVE-2005-3191: Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing c Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) l
osv
CVE-2005-3193P4MEDIUMCVSS 5.1≥ 0, < 0.5.8-12005-12-07
CVE-2005-3193 [MEDIUM] CVE-2005-3193: Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code
osv
CVE-2018-20431P4MEDIUMCVSS 6.5≤ 1.82018-12-24
CVE-2018-20431 [MEDIUM] CWE-476 CVE-2018-20431: GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_me GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.
nvdosv
Gnu Libextractor vulnerabilities | cvebase