Vulnerabilities > Freedesktop > Poppler > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-02 CVE-2017-14976 Out-of-bounds Read vulnerability in multiple products
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.
network
low complexity
freedesktop debian CWE-125
7.5
2017-10-02 CVE-2017-14975 NULL Pointer Dereference vulnerability in multiple products
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.
network
low complexity
freedesktop debian CWE-476
7.5
2017-09-30 CVE-2017-14929 Infinite Loop vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.
network
low complexity
freedesktop CWE-835
7.5
2017-09-20 CVE-2017-14617 Improper Input Validation vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.
local
low complexity
freedesktop CWE-20
7.8
2017-09-17 CVE-2017-14520 Improper Input Validation vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
local
low complexity
freedesktop CWE-20
7.8
2017-09-17 CVE-2017-14519 Infinite Loop vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop).
network
low complexity
freedesktop CWE-835
7.5
2017-09-17 CVE-2017-14518 Improper Input Validation vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
local
low complexity
freedesktop CWE-20
7.8
2017-07-12 CVE-2017-2820 Integer Overflow or Wraparound vulnerability in Freedesktop Poppler 0.53.0
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0.
network
low complexity
freedesktop CWE-190
8.8
2017-07-12 CVE-2017-2818 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freedesktop Poppler 0.53.0
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
network
low complexity
freedesktop CWE-119
8.8
2017-07-12 CVE-2017-2814 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freedesktop Poppler 0.53.0
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0.
network
low complexity
freedesktop CWE-119
8.8