6.8
CVSSv2

CVE-2019-1010006

Published: 15/07/2019 Updated: 02/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that Evince incorrectly handled certain PDF files. An attacker could possibly use this issue to cause a denial of service or to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome evince 3.26.0

canonical ubuntu linux 16.04

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Evince could be made to crash or run arbitrary code if it received a specially crafted PDF file ...
Several vulnerabilities were discovered in evince, a simple multi-page document viewer CVE-2017-1000159 Tobias Mueller reported that the DVI exporter in evince is susceptible to a command injection vulnerability via specially crafted filenames CVE-2019-11459 Andy Nguyen reported that the tiff_document_render() and tiff_docume ...
Impact: Moderate Public Date: 2019-07-14 CWE: CWE-120->(CWE-400|CWE-94) Bugzilla: 1730582: CVE-2019- ...