Vulnerabilities > Xpdfreader > Xpdf > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-30 CVE-2022-41844 Out-of-bounds Write vulnerability in Xpdfreader Xpdf 4.04
An issue was discovered in Xpdf 4.04.
local
low complexity
xpdfreader CWE-787
5.5
2022-09-15 CVE-2022-38334 Uncontrolled Recursion vulnerability in Xpdfreader Xpdf
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
local
low complexity
xpdfreader CWE-674
5.5
2022-08-30 CVE-2022-36561 Unspecified vulnerability in Xpdfreader Xpdf 4.04
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
local
low complexity
xpdfreader
5.5
2022-05-18 CVE-2021-27548 NULL Pointer Dereference vulnerability in Xpdfreader Xpdf 4.03
There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
local
low complexity
xpdfreader CWE-476
5.5
2022-05-16 CVE-2022-30775 Allocation of Resources Without Limits or Throttling vulnerability in Xpdfreader Xpdf 4.04
xpdf 4.04 allocates excessive memory when presented with crafted input.
local
low complexity
xpdfreader CWE-770
5.5
2022-04-25 CVE-2022-27135 Out-of-bounds Write vulnerability in Xpdfreader Xpdf 4.03
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc.
local
low complexity
xpdfreader CWE-787
5.5
2020-11-21 CVE-2020-25725 In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem.
local
low complexity
xpdfreader fedoraproject
5.5
2019-10-30 CVE-2010-0207 Infinite Loop vulnerability in Xpdfreader Xpdf 3.0317/3.0413/3.044
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
local
low complexity
xpdfreader CWE-835
5.5
2019-10-30 CVE-2010-0206 NULL Pointer Dereference vulnerability in Xpdfreader Xpdf 3.0317/3.0413/3.044
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
local
low complexity
xpdfreader CWE-476
5.5
2019-03-25 CVE-2019-10026 Divide By Zero vulnerability in Xpdfreader Xpdf 4.01.01
An issue was discovered in Xpdf 4.01.01.
local
low complexity
xpdfreader CWE-369
5.5