Vulnerabilities > Freedesktop > Poppler

DATE CVE VULNERABILITY TITLE RISK
2022-08-22 CVE-2022-38171 Integer Overflow or Wraparound vulnerability in multiple products
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).
local
low complexity
xpdfreader freedesktop CWE-190
7.8
2022-05-05 CVE-2022-27337 A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
network
low complexity
freedesktop fedoraproject debian
6.5
2021-08-24 CVE-2021-30860 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow was addressed with improved input validation.
local
low complexity
apple xpdfreader freedesktop CWE-190
7.8
2020-12-25 CVE-2020-35702 Out-of-bounds Write vulnerability in Freedesktop Poppler 20.12.1
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document.
local
low complexity
freedesktop CWE-787
7.8
2020-12-03 CVE-2020-27778 Access of Uninitialized Pointer vulnerability in multiple products
A flaw was found in Poppler in the way certain PDF files were converted into HTML.
network
low complexity
freedesktop redhat debian CWE-824
7.5
2020-01-09 CVE-2012-2142 Security vulnerability in Poppler and xpdf
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
6.8
2019-11-13 CVE-2010-4654 Injection vulnerability in multiple products
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
network
freedesktop debian CWE-74
critical
9.3
2019-11-13 CVE-2010-4653 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
network
low complexity
freedesktop debian CWE-190
6.5
2019-09-05 CVE-2018-21009 Integer Overflow or Wraparound vulnerability in Freedesktop Poppler
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
6.8
2019-08-01 CVE-2019-14494 Divide By Zero vulnerability in multiple products
An issue was discovered in Poppler through 0.78.0.
7.5