Vulnerabilities > Freedesktop

DATE CVE VULNERABILITY TITLE RISK
2017-09-17 CVE-2017-14517 NULL Pointer Dereference vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
local
low complexity
freedesktop CWE-476
5.5
2017-07-12 CVE-2017-2820 Integer Overflow or Wraparound vulnerability in Freedesktop Poppler 0.53.0
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.
network
low complexity
freedesktop CWE-190
8.8
2017-07-12 CVE-2017-2818 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freedesktop Poppler 0.53.0
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
network
low complexity
freedesktop CWE-119
8.8
2017-07-12 CVE-2017-2814 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freedesktop Poppler 0.53.0
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
network
low complexity
freedesktop CWE-119
8.8
2017-06-25 CVE-2017-9865 Out-of-bounds Read vulnerability in multiple products
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.
local
low complexity
freedesktop debian CWE-125
5.5
2017-06-22 CVE-2017-9776 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
local
low complexity
freedesktop debian redhat CWE-190
7.8
2017-06-22 CVE-2017-9775 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
network
low complexity
freedesktop debian redhat CWE-119
6.5
2017-06-06 CVE-2017-7515 Uncontrolled Recursion vulnerability in Freedesktop Poppler
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
local
low complexity
freedesktop CWE-674
5.5
2017-06-02 CVE-2017-9408 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
network
low complexity
freedesktop debian CWE-772
6.5
2017-06-02 CVE-2017-9406 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
network
low complexity
freedesktop debian CWE-772
6.5