Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 50% | — | Artifex MupdfFedoraproject FedoraDebian Linux | 23/2/2021 | 17/6/2026 | A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences. | |
| Modificada | Alta (7.8) | 0.96% | — | Artifex Mupdf | 9/12/2020 | 17/6/2026 | A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer. | |
| Modificada | Media (5.5) | 1.0% | — | Artifex MupdfDebian LinuxFedoraproject Fedora | 2/10/2020 | 17/6/2026 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service. | |
| Modificada | Alta (7.8) | 5.7% | 💥 Exploit | Sumatrapdfreader SumatrapdfArtifex Mupdf | 23/1/2020 | 16/6/2026 | SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file. | |
| Modificada | Alta (7.1) | 1.1% | — | Artifex Mupdf | 14/8/2019 | 17/6/2026 | Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string. | |
| Modificada | Alta (7.8) | 3.0% | — | Artifex Mupdf | 4/7/2019 | 17/6/2026 | Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node. | |
| Modificada | Crítica (9.8) | 3.2% | — | Artifex Mupdf | 13/6/2019 | 17/6/2026 | Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex Mupdf | 11/1/2019 | 17/6/2026 | svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex Mupdf | 11/1/2019 | 17/6/2026 | Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex Mupdf | 6/12/2018 | 17/6/2026 | In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex Mupdf | 6/12/2018 | 17/6/2026 | In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl. | |
| Modificada | Media (5.5) | 1.1% | — | Artifex MupdfDebian Linux | 30/11/2018 | 17/6/2026 | In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex Mupdf | 26/10/2018 | 17/6/2026 | There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex Mupdf | 6/9/2018 | 17/6/2026 | In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex Mupdf | 6/9/2018 | 17/6/2026 | In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex MupdfDebian Linux | 24/5/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file. | |
| Modificada | Media (6.3) | 1.8% | — | Artifex Mupdf | 24/5/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file. | |
| Modificada | Alta (7.8) | 1.9% | — | Artifex Mupdf | 24/5/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex MupdfDebian Linux | 24/5/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file. | |
| Modificada | Media (5.5) | 0.97% | — | Artifex MupdfDebian Linux | 24/5/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file. | |
| Modificada | Alta (7.8) | 1.5% | — | Artifex Mupdf | 24/4/2018 | 17/6/2026 | An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential code execution. An attacker can specially craft a PDF and send to the victim to trigger this… | |
| Modificada | Alta (7.8) | 1.7% | — | Artifex Mupdf | 24/4/2018 | 17/6/2026 | An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially… | |
| Modificada | Media (5.5) | 1.1% | — | Artifex MupdfDebian Linux | 22/4/2018 | 17/6/2026 | In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file. | |
| Modificada | Alta (7.8) | 1.7% | — | Artifex MupdfDebian Linux | 9/2/2018 | 17/6/2026 | Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex MupdfDebian Linux | 2/2/2018 | 17/6/2026 | pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document. |