XpdfReader Xpdf 3.02 pl1

CPE Details

XpdfReader Xpdf 3.02 pl1
3.02
2020-12-23
18h25 +00:00
2020-12-23
18h25 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:xpdfreader:xpdf:3.02:pl1:*:*:*:*:*:*

Informations

Vendor

xpdfreader

Product

xpdf

Version

3.02

Update

pl1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-7868 2024-08-15 20h22 +00:00 In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
2.1
Bas
CVE-2024-7867 2024-08-15 20h06 +00:00 In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
2.1
Bas
CVE-2024-7866 2024-08-15 19h50 +00:00 In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.
2.1
Bas
CVE-2024-4976 2024-05-15 20h34 +00:00 Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
2.1
Bas
CVE-2024-4568 2024-05-06 19h56 +00:00 In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
5.5
Moyen
CVE-2024-4141 2024-04-24 18h36 +00:00 Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.
5.5
Moyen
CVE-2024-3900 2024-04-17 18h41 +00:00 Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
5.5
Moyen
CVE-2024-3248 2024-04-02 23h04 +00:00 In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.
5.5
Moyen
CVE-2024-3247 2024-04-02 22h57 +00:00 In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.
5.5
Moyen
CVE-2024-2971 2024-03-26 21h31 +00:00 Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.
5.5
Moyen
CVE-2023-3044 2023-06-02 22h32 +00:00 An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate.
3.3
Bas
CVE-2023-2664 2023-05-11 20h21 +00:00  In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.
5.5
Moyen
CVE-2023-2663 2023-05-11 20h16 +00:00  In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.
9.1
Critique
CVE-2023-2662 2023-05-11 20h08 +00:00 In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.
5.5
Moyen
CVE-2022-38334 2022-09-14 22h00 +00:00 XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
5.5
Moyen
CVE-2021-30860 2021-08-24 18h49 +00:00 An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
7.8
Haute
CVE-2012-2142 2020-01-09 19h42 +00:00 The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
7.8
Haute
CVE-2010-3702 2010-11-05 16h00 +00:00 The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
7.5
CVE-2007-3387 2007-07-30 21h00 +00:00 Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
6.8