Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
freedesktop poppler vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv3
CVE-2017-9865
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote malicious users to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.
Freedesktop Poppler 0.54.0
Debian Debian Linux 8.0
Debian Debian Linux 9.0
5.5
CVSSv3
CVE-2017-7515
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
Freedesktop Poppler
6.5
CVSSv3
CVE-2017-9406
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows malicious users to cause a denial of service via a crafted file.
Freedesktop Poppler 0.54.0
Debian Debian Linux 8.0
Debian Debian Linux 9.0
6.5
CVSSv3
CVE-2017-9408
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows malicious users to cause a denial of service via a crafted file.
Freedesktop Poppler 0.54.0
Debian Debian Linux 8.0
Debian Debian Linux 9.0
5.5
CVSSv3
CVE-2017-7511
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.
Freedesktop Poppler 0.44.0
Freedesktop Poppler 0.28.1
Freedesktop Poppler 0.31.0
Freedesktop Poppler 0.23.1
Freedesktop Poppler 0.50.0
Freedesktop Poppler 0.24.4
Freedesktop Poppler 0.21.3
Freedesktop Poppler 0.22.5
Freedesktop Poppler 0.18.4
Freedesktop Poppler 0.22.3
Freedesktop Poppler 0.24.1
Freedesktop Poppler 0.26.5
Freedesktop Poppler 0.25.0
Freedesktop Poppler 0.24.0
Freedesktop Poppler 0.48.0
Freedesktop Poppler 0.20.1
Freedesktop Poppler 0.51.0
Freedesktop Poppler 0.17.3
Freedesktop Poppler 0.53.0
Freedesktop Poppler 0.34.0
Freedesktop Poppler 0.25.3
Freedesktop Poppler 0.39.0
6.5
CVSSv3
CVE-2017-9083
poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.
Freedesktop Poppler 0.54.0
NA
CVE-2010-5110
DCTStream.cc in Poppler prior to 0.13.3 allows remote malicious users to cause a denial of service (crash) via a crafted PDF file.
Freedesktop Poppler 0.13.1
Freedesktop Poppler 0.13.0
Freedesktop Poppler
NA
CVE-2013-4472
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and previous versions, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Freedesktop Poppler 0.24.1
Freedesktop Poppler 0.24.0
Freedesktop Poppler
Freedesktop Poppler 0.24.2
NA
CVE-2013-7296
The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler prior to 0.24.5 does not use the correct specifier within a format string, which allows context-dependent malicious users to cause a denial of service (segmentation fault and application crash) via a crafted PDF fi...
Freedesktop Poppler 0.16.4
Freedesktop Poppler 0.12.1
Freedesktop Poppler 0.14.3
Freedesktop Poppler 0.11.0
Freedesktop Poppler 0.16.7
Freedesktop Poppler 0.23.1
Freedesktop Poppler 0.10.2
Freedesktop Poppler 0.12.2
Freedesktop Poppler 0.21.3
Freedesktop Poppler 0.18.4
Freedesktop Poppler 0.10.6
Freedesktop Poppler 0.13.3
Freedesktop Poppler 0.22.3
Freedesktop Poppler 0.24.1
Freedesktop Poppler 0.16.0
Freedesktop Poppler 0.10.1
Freedesktop Poppler 0.11.1
Freedesktop Poppler 0.24.0
Freedesktop Poppler 0.17.1
Freedesktop Poppler 0.13.1
Freedesktop Poppler 0.20.1
Freedesktop Poppler 0.10.0
NA
CVE-2013-4473
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler prior to 0.24.2 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.
Freedesktop Poppler 0.16.4
Freedesktop Poppler 0.12.1
Freedesktop Poppler 0.14.3
Freedesktop Poppler 0.11.0
Freedesktop Poppler 0.16.7
Freedesktop Poppler 0.23.1
Freedesktop Poppler 0.10.2
Freedesktop Poppler 0.6.4
Freedesktop Poppler 0.8.2
Freedesktop Poppler 0.12.2
Freedesktop Poppler 0.21.3
Freedesktop Poppler 0.8.6
Freedesktop Poppler 0.18.4
Freedesktop Poppler 0.10.6
Freedesktop Poppler 0.13.3
Freedesktop Poppler 0.22.3
Freedesktop Poppler 0.5.9
Freedesktop Poppler 0.16.0
Freedesktop Poppler 0.10.1
Freedesktop Poppler 0.11.1
Freedesktop Poppler 0.24.0
Freedesktop Poppler 0.17.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
NEXT »