Mate-Desktop Atril vulnerabilities
6 known vulnerabilities affecting mate-desktop/atril.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-1010006HIGHCVSS 7.8≥ 0, < 1.20.1-2ubuntu2+esm2≥ 0, < 1.24.0-1ubuntu0.2+1 more2025-02-18
CVE-2019-1010006 [HIGH] atril vulnerabilities
atril vulnerabilities
It was discovered that Atril incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service
or to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)
Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-1
osv
CVE-2023-52076HIGHCVSS 7.8fixed in 1.26.22024-01-25
CVE-2023-52076 [HIGH] CWE-22 CVE-2023-52076: Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A pa
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitat
cvelistv5nvdosv
CVE-2023-51698HIGHCVSS 8.8≤ 1.26.32024-01-12
CVE-2023-51698 [HIGH] CWE-78 CVE-2023-51698: Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vu
Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a maliciously crafted CBT document which is a TAR archive. A patch is available a
cvelistv5nvdosv
CVE-2019-11459MEDIUMCVSS 5.5≥ 0, < 1.22.3-12019-04-22
CVE-2019-11459 [MEDIUM] CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
osv
CVE-2017-1000159HIGHCVSS 7.8≥ 0, < 1.20.0-12017-11-27
CVE-2017-1000159 [HIGH] CVE-2017-1000159: Command injection in evince via filename when printing to PDF
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
osv
CVE-2017-1000083HIGHCVSS 7.8PoC≥ 0, < 1.16.1-2.12017-09-05
CVE-2017-1000083 [HIGH] CVE-2017-1000083: backend/comics/comics-document
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
osv