Vulnerabilities > Artifex > Mupdf > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-12-06 CVE-2018-19882 NULL Pointer Dereference vulnerability in Artifex Mupdf 1.14.0
In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.
local
low complexity
artifex CWE-476
5.5
2018-12-06 CVE-2018-19881 Resource Exhaustion vulnerability in Artifex Mupdf 1.14.0
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
local
low complexity
artifex CWE-400
5.5
2018-11-30 CVE-2018-19777 Infinite Loop vulnerability in multiple products
In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.
local
low complexity
artifex debian CWE-835
5.5
2018-10-26 CVE-2018-18662 Out-of-bounds Read vulnerability in Artifex Mupdf 1.14.0
There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
local
low complexity
artifex CWE-125
5.5
2018-09-06 CVE-2018-16648 Improper Validation of Array Index vulnerability in Artifex Mupdf 1.13.0
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file.
local
low complexity
artifex CWE-129
5.5
2018-09-06 CVE-2018-16647 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Mupdf 1.13.0
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.
local
low complexity
artifex CWE-119
5.5
2018-05-24 CVE-2018-1000040 Improper Input Validation vulnerability in multiple products
In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.
local
low complexity
artifex debian CWE-20
5.5
2018-05-24 CVE-2018-1000037 Improper Input Validation vulnerability in multiple products
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
local
low complexity
artifex debian CWE-20
5.5
2018-05-24 CVE-2018-1000036 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
local
low complexity
artifex debian CWE-772
5.5
2018-04-22 CVE-2018-10289 Infinite Loop vulnerability in multiple products
In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file.
local
low complexity
artifex debian CWE-835
5.5