Xpdfreader Xpdf vulnerabilities

82 known vulnerabilities affecting xpdfreader/xpdf.

Total CVEs
82
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH16MEDIUM60LOW6

Vulnerabilities

Page 4 of 5
CVE-2018-18455MEDIUMCVSS 5.5v4.002018-10-18
CVE-2018-18455 [MEDIUM] CWE-125 CVE-2018-18455: The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
nvd
CVE-2018-18457MEDIUMCVSS 5.5v4.002018-10-18
CVE-2018-18457 [MEDIUM] CWE-476 CVE-2018-18457: The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
nvd
CVE-2018-16369MEDIUMCVSS 5.5v4.002018-09-03
CVE-2018-16369 [MEDIUM] CVE-2018-16369: XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack cons XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.
nvd
CVE-2018-16368MEDIUMCVSS 5.5v4.002018-09-03
CVE-2018-16368 [MEDIUM] CWE-125 CVE-2018-16368: SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a d SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.
nvd
CVE-2018-11033HIGHCVSS 7.8v4.002018-05-14
CVE-2018-11033 [HIGH] CWE-119 CVE-2018-11033: The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remot The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.
nvd
CVE-2018-8100HIGHCVSS 7.8v4.002018-03-14
CVE-2018-8100 [HIGH] CWE-787 CVE-2018-8100: The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8101MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8101 [MEDIUM] CWE-125 CVE-2018-8101: The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launc The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8102MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8102 [MEDIUM] CWE-125 CVE-2018-8102: The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8107MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8107 [MEDIUM] CWE-125 CVE-2018-8107: The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of serv The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8104MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8104 [MEDIUM] CWE-125 CVE-2018-8104: The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of serv The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8105MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8105 [MEDIUM] CWE-125 CVE-2018-8105: The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial o The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8106MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8106 [MEDIUM] CWE-125 CVE-2018-8106: The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch den The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-8103MEDIUMCVSS 5.5v4.002018-03-14
CVE-2018-8103 [MEDIUM] CWE-125 CVE-2018-8103: The JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launc The JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-7453MEDIUMCVSS 5.5v4.002018-02-24
CVE-2018-7453 [MEDIUM] CWE-835 CVE-2018-7453: Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch den Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.
nvd
CVE-2018-7454MEDIUMCVSS 5.5v4.002018-02-24
CVE-2018-7454 [MEDIUM] CWE-476 CVE-2018-7454: A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to lau A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-7452MEDIUMCVSS 5.5v4.002018-02-24
CVE-2018-7452 [MEDIUM] CWE-476 CVE-2018-7452: A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers t A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-7455MEDIUMCVSS 5.5v4.002018-02-24
CVE-2018-7455 [MEDIUM] CWE-125 CVE-2018-7455: An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to la An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
nvd
CVE-2018-7173MEDIUMCVSS 5.5v4.002018-02-15
CVE-2018-7173 [MEDIUM] CWE-172 CVE-2018-7173: A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of se A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.
nvd
CVE-2018-7174MEDIUMCVSS 5.5v4.002018-02-15
CVE-2018-7174 [MEDIUM] CWE-835 CVE-2018-7174: An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause den An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
nvd
CVE-2018-7175MEDIUMCVSS 5.5v4.002018-02-15
CVE-2018-7175 [MEDIUM] CWE-476 CVE-2018-7175: An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacke An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
nvd