Search CVE reports
111 – 120 of 198 results
CVE-2018-8101
Negligible priorityThe JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-8100
Negligible priorityThe JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file,...
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7455
Negligible priorityAn out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7454
Negligible priorityA NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7453
Negligible priorityInfinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7452
Negligible priorityA NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7175
Negligible priorityAn issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7174
Negligible priorityAn issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2018-7173
Negligible priorityA large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.
4 affected packages
ipe, libextractor, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
libextractor | Not affected | Not affected | Not affected | Not affected | Not affected |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Vulnerable | Vulnerable | Not in release | Vulnerable | Vulnerable |
CVE-2017-1000456
Medium priorityfreedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | — | — | — | — | Fixed |