XpdfReader Xpdf 0.91a

CPE Details

XpdfReader Xpdf 0.91a
0.91a
2020-12-23 18:25 +00:00
2020-12-23 18:25 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:xpdfreader:xpdf:0.91a:*:*:*:*:*:*:*

Informations

Vendor

xpdfreader

Product

xpdf

Version

0.91a

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-3044 2023-06-02 22:32 +00:00 An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate.
3.3
LOW
CVE-2023-2664 2023-05-11 20:21 +00:00  In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.
5.5
MEDIUM
CVE-2023-2663 2023-05-11 20:16 +00:00  In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.
5.5
MEDIUM
CVE-2023-2662 2023-05-11 20:08 +00:00 In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
5.5
MEDIUM
CVE-2022-38334 2022-09-14 22:00 +00:00 XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
5.5
MEDIUM
CVE-2021-30860 2021-08-24 16:49 +00:00 An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
7.8
HIGH
CVE-2010-3702 2010-11-05 16:00 +00:00 The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
7.5
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.