Search CVE reports
1 – 10 of 200 results
CVE-2025-32365
Medium prioritySome fixes available 4 of 6
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | Fixed | Fixed | Fixed | Needs evaluation | Needs evaluation |
CVE-2025-32364
Medium prioritySome fixes available 4 of 6
A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | Fixed | Fixed | Fixed | Needs evaluation | Needs evaluation |
CVE-2024-56378
Medium prioritylibpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2024-6239
Low prioritySome fixes available 2 of 6
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | Fixed | Fixed | Ignored | Ignored | Ignored |
CVE-2024-3900
Medium priorityOut-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
3 affected packages
ipe, poppler, xpdf
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ipe | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
poppler | Not affected | Not affected | Not affected | Not affected | Not affected |
xpdf | Not affected | Not affected | Not in release | Not affected | Not affected |
CVE-2022-38349
Medium priorityAn issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-37052
Medium priorityA reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-37051
Medium priorityAn issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | — | Fixed | Fixed | Fixed | Fixed |
CVE-2022-37050
Medium priorityIn Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing....
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | — | Fixed | Fixed | Fixed | Fixed |
CVE-2020-23804
Medium priorityUncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
1 affected package
poppler
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
poppler | — | Not affected | Fixed | Fixed | Fixed |