Vulnerabilities > Glyphandcog

DATE CVE VULNERABILITY TITLE RISK
2019-03-06 CVE-2019-9588 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Glyphandcog Xpdfreader 4.01
There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01.
6.8
2019-03-06 CVE-2019-9587 Resource Exhaustion vulnerability in Glyphandcog Xpdfreader 4.01
There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01.
6.8
2018-01-30 CVE-2011-2902 Improper Input Validation vulnerability in multiple products
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
network
low complexity
glyphandcog debian CWE-20
6.4
2011-03-31 CVE-2011-1554 Numeric Errors vulnerability in multiple products
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.
4.3
2011-03-31 CVE-2011-1553 Resource Management Errors vulnerability in multiple products
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.
4.3
2011-03-31 CVE-2011-1552 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.
4.3
2011-03-31 CVE-2011-0764 Improper Input Validation vulnerability in multiple products
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.
6.8
2010-11-05 CVE-2010-3704 Improper Input Validation vulnerability in multiple products
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
6.8
2009-04-23 CVE-2009-0165 Numeric Errors vulnerability in multiple products
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
network
low complexity
foolabs glyphandcog poppler CWE-189
critical
10.0
2009-04-23 CVE-2009-1182 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
network
low complexity
foolabs glyphandcog poppler apple CWE-119
7.5