Vulnerabilities > Glyph AND COG

DATE CVE VULNERABILITY TITLE RISK
2009-10-21 CVE-2009-3609 Numeric Errors vulnerability in multiple products
Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.
4.3
2009-10-21 CVE-2009-3608 Numeric Errors vulnerability in multiple products
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
9.3
2007-12-15 CVE-2007-6358 Unspecified vulnerability in Glyph and COG Pdftops
pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.
local
low complexity
glyph-and-cog
4.9