Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
poppler vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv3
CVE-2017-7515
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
Freedesktop Poppler
5.5
CVSSv3
CVE-2017-7511
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.
Freedesktop Poppler 0.54.0
Freedesktop Poppler 0.53.0
Freedesktop Poppler 0.52.0
Freedesktop Poppler 0.45.0
Freedesktop Poppler 0.44.0
Freedesktop Poppler 0.37.0
Freedesktop Poppler 0.36.0
Freedesktop Poppler 0.28.1
Freedesktop Poppler 0.28.0
Freedesktop Poppler 0.25.3
Freedesktop Poppler 0.25.2
Freedesktop Poppler 0.24.1
Freedesktop Poppler 0.24.0
Freedesktop Poppler 0.22.3
Freedesktop Poppler 0.22.2
Freedesktop Poppler 0.21.0
Freedesktop Poppler 0.20.5
Freedesktop Poppler 0.19.3
Freedesktop Poppler 0.19.2
Freedesktop Poppler 0.17.4
Freedesktop Poppler 0.17.3
Freedesktop Poppler 0.55.0
NA
CVE-2010-5110
DCTStream.cc in Poppler prior to 0.13.3 allows remote malicious users to cause a denial of service (crash) via a crafted PDF file.
Freedesktop Poppler 0.13.0
Freedesktop Poppler
Freedesktop Poppler 0.13.1
NA
CVE-2013-4472
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and previous versions, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Freedesktop Poppler 0.24.0
Freedesktop Poppler 0.24.2
Freedesktop Poppler 0.24.1
Freedesktop Poppler
NA
CVE-2013-7296
The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler prior to 0.24.5 does not use the correct specifier within a format string, which allows context-dependent malicious users to cause a denial of service (segmentation fault and application crash) via a crafted PDF fi...
Freedesktop Poppler 0.23.3
Freedesktop Poppler 0.23.2
Freedesktop Poppler 0.22.0
Freedesktop Poppler 0.21.4
Freedesktop Poppler 0.20.3
Freedesktop Poppler 0.20.2
Freedesktop Poppler 0.19.0
Freedesktop Poppler 0.18.4
Freedesktop Poppler 0.17.2
Freedesktop Poppler 0.17.1
Freedesktop Poppler 0.16.2
Freedesktop Poppler 0.16.1
Freedesktop Poppler 0.14.3
Freedesktop Poppler 0.14.2
Freedesktop Poppler 0.13.0
Freedesktop Poppler 0.12.4
Freedesktop Poppler 0.11.1
Freedesktop Poppler 0.11.0
Freedesktop Poppler 0.10.0
Freedesktop Poppler 0.1.2
Freedesktop Poppler
Freedesktop Poppler 0.24.2
NA
CVE-2013-4473
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler prior to 0.24.2 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.
Freedesktop Poppler 0.22.4
Freedesktop Poppler 0.22.3
Freedesktop Poppler 0.1
Freedesktop Poppler 0.1.1
Freedesktop Poppler 0.11.3
Freedesktop Poppler 0.12.0
Freedesktop Poppler 0.12.1
Freedesktop Poppler 0.12.2
Freedesktop Poppler 0.12.3
Freedesktop Poppler 0.15.0
Freedesktop Poppler 0.15.1
Freedesktop Poppler 0.15.2
Freedesktop Poppler 0.15.3
Freedesktop Poppler 0.18.0
Freedesktop Poppler 0.18.1
Freedesktop Poppler 0.18.2
Freedesktop Poppler 0.18.3
Freedesktop Poppler 0.21.0
Freedesktop Poppler 0.21.1
Freedesktop Poppler 0.21.2
Freedesktop Poppler 0.21.3
Freedesktop Poppler 0.4.4
NA
CVE-2013-4474
Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler prior to 0.24.3 allows remote malicious users to cause a denial of service (crash) via format string specifiers in a destination filename.
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 15.10
Freedesktop Poppler 0.24.0
Freedesktop Poppler 0.23.4
Freedesktop Poppler 0.1
Freedesktop Poppler 0.1.1
Freedesktop Poppler 0.10.5
Freedesktop Poppler 0.10.6
Freedesktop Poppler 0.12.2
Freedesktop Poppler 0.12.3
Freedesktop Poppler 0.14.0
Freedesktop Poppler 0.14.1
Freedesktop Poppler 0.15.2
Freedesktop Poppler 0.15.3
Freedesktop Poppler 0.16.7
Freedesktop Poppler 0.17.0
Freedesktop Poppler 0.18.2
Freedesktop Poppler 0.18.3
Freedesktop Poppler 0.2.0
Freedesktop Poppler 0.20.0
Freedesktop Poppler 0.20.1
1 EDB exploit
NA
CVE-2013-1788
poppler prior to 0.22.1 allows context-dependent malicious users to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc.
Freedesktop Poppler
NA
CVE-2013-1790
poppler/Stream.cc in poppler prior to 0.22.1 allows context-dependent malicious users to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
Freedesktop Poppler
NA
CVE-2013-1789
splash/Splash.cc in poppler prior to 0.22.1 allows context-dependent malicious users to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.
Freedesktop Poppler
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »