Glyphandcog
Glyphandcog Xpdfreader: vulnerabilidades y CVE
Glyphandcog Xpdfreader tiene 53 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE53
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40226 | Alta (7.5) | 0.75% | — | 10 nov 2022 | xpdfreader 4.03 is vulnerable to Buffer Overflow. |
| CVE-2022-24107 | Alta (7.8) | 0.31% | — | 30 ago 2022 | Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. |
| CVE-2022-24106 | Alta (7.8) | 0.31% | — | 30 ago 2022 | In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc. |
| CVE-2019-17064 | Media (5.5) | 1.4% | — | 1 oct 2019 | Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. |
| CVE-2019-16115 | Alta (7.8) | 1.1% | — | 8 sept 2019 | In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document… |
| CVE-2019-16088 | Media (5.5) | 0.91% | — | 6 sept 2019 | Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc. |
| CVE-2019-15860 | Media (5.5) | 0.87% | — | 3 sept 2019 | Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002. |
| CVE-2019-14294 | Media (5.5) | 0.95% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read. |
| CVE-2019-14293 | Media (5.5) | 0.95% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2. |
| CVE-2019-14292 | Media (5.5) | 1.1% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1. |
| CVE-2019-14291 | Media (5.5) | 0.95% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3. |
| CVE-2019-14290 | Media (5.5) | 0.95% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2. |
| CVE-2019-14289 | Media (5.5) | 0.95% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case. |
| CVE-2019-14288 | Alta (7.8) | 1.0% | — | 27 jul 2019 | An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case. |
| CVE-2019-13291 | Media (5.5) | 1.1% | — | 4 jul 2019 | In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow… |
| CVE-2019-13289 | Alta (7.8) | 1.1% | — | 4 jul 2019 | In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. |
| CVE-2019-13288 | Media (5.5) | 4.6% | — | 4 jul 2019 | In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646. |
| CVE-2019-13287 | Media (5.5) | 1.2% | — | 4 jul 2019 | In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the… |
| CVE-2019-13286 | Media (5.5) | 1.1% | — | 4 jul 2019 | In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm… |
| CVE-2019-13283 | Alta (7.8) | 1.1% | — | 4 jul 2019 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy.… |
| CVE-2019-13282 | Alta (7.8) | 1.1% | — | 4 jul 2019 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to… |
| CVE-2019-13281 | Alta (7.8) | 1.2% | — | 4 jul 2019 | In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the… |
| CVE-2019-12958 | Media (5.5) | 1.2% | — | 25 jun 2019 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has… |
| CVE-2019-12957 | Alta (7.8) | 1.2% | — | 25 jun 2019 | In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a… |
| CVE-2019-12515 | Alta (7.1) | 1.3% | — | 2 jun 2019 | There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It… |
| CVE-2019-12493 | Alta (7.1) | 1.3% | — | 31 may 2019 | A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be… |
| CVE-2019-12360 | Alta (7.1) | 1.1% | — | 27 may 2019 | A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It… |
| CVE-2019-9589 | Alta (7.8) | 1.2% | — | 6 mar 2019 | There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows… |
| CVE-2019-9588 | Alta (7.8) | 1.2% | — | 6 mar 2019 | There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of… |
| CVE-2019-9587 | Alta (7.8) | 1.2% | — | 6 mar 2019 | There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of… |