Vulnerabilities > Poppler > Poppler > 0.10.1

DATE CVE VULNERABILITY TITLE RISK
2010-11-05 CVE-2010-3704 Improper Input Validation vulnerability in multiple products
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
6.8
2010-11-05 CVE-2010-3703 Improper Input Validation vulnerability in Poppler
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.
network
poppler CWE-20
4.3
2009-04-23 CVE-2009-1182 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
network
low complexity
foolabs glyphandcog poppler apple CWE-119
7.5
2009-04-23 CVE-2009-1180 Resource Management Errors vulnerability in multiple products
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
6.8
2009-04-23 CVE-2009-0799 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.
4.3
2009-04-23 CVE-2009-0166 Resource Management Errors vulnerability in multiple products
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.
4.3
2009-03-03 CVE-2009-0756 Denial of Service vulnerability in Poppler
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.
network
low complexity
poppler
5.0
2009-03-03 CVE-2009-0755 Denial of Service vulnerability in Poppler
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.
network
low complexity
poppler
5.0