Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Freedesktop PopplerDebian Linux | 22/8/2023 | 17/6/2026 | Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input. | |
| Modificada | Media (6.5) | 0.65% | — | Freedesktop Poppler | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service. | |
| Modificada | Media (5.5) | 0.53% | — | Freedesktop Poppler | 11/8/2023 | 17/6/2026 | An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function. | |
| Modificada | Media (6.5) | 1.2% | — | Freedesktop Poppler | 11/8/2023 | 17/6/2026 | An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function. | |
| Modificada | Media (5.5) | 0.90% | — | Freedesktop Poppler | 31/7/2023 | 17/6/2026 | A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open. | |
| Modificada | Alta (7.8) | 0.63% | — | Freedesktop PopplerDebian LinuxFedoraproject Fedora | 30/8/2022 | 17/6/2026 | Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171… | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdfreader XpdfFreedesktop Poppler | 22/8/2022 | 17/6/2026 | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple… | |
| Modificada | Media (6.5) | 1.6% | — | Freedesktop PopplerFedoraproject FedoraDebian Linux | 5/5/2022 | 17/6/2026 | A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Analizada | Alta (7.8) | 76% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+3 | 24/8/2021 | 17/6/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been… | |
| Modificada | Alta (7.8) | 0.87% | — | Freedesktop Poppler | 25/12/2020 | 17/6/2026 | DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability.… | |
| Modificada | Alta (7.5) | 2.2% | — | Freedesktop PopplerRedhat Enterprise LinuxDebian Linux | 3/12/2020 | 17/6/2026 | A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service. | |
| Modificada | Alta (7.8) | 2.9% | — | Freedesktop PopplerXpdfreader XpdfRedhat Enterprise LinuxOpensuse | 9/1/2020 | 16/6/2026 | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | |
| Modificada | Alta (7.8) | 1.2% | — | Freedesktop PopplerDebian Linux | 13/11/2019 | 16/6/2026 | poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. | |
| Modificada | Media (6.5) | 1.8% | — | Freedesktop PopplerDebian Linux | 13/11/2019 | 16/6/2026 | An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts. | |
| Modificada | Alta (8.8) | 1.9% | — | Freedesktop Poppler | 5/9/2019 | 17/6/2026 | Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. | |
| Modificada | Alta (7.5) | 2.7% | — | Freedesktop PopplerCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+1 | 1/8/2019 | 17/6/2026 | An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. | |
| Modificada | Media (6.5) | 1.9% | — | Freedesktop PopplerDebian LinuxFedoraproject FedoraRedhat Enterprise Linux+3 | 22/7/2019 | 17/6/2026 | The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo. | |
| Modificada | Alta (8.8) | 2.1% | — | Freedesktop Poppler | 23/5/2019 | 17/6/2026 | In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. | |
| Modificada | Media (6.5) | 1.8% | — | Freedesktop PopplerFedoraproject Fedora | 8/4/2019 | 17/6/2026 | FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc. | |
| Modificada | Media (6.5) | 2.6% | — | Freedesktop Poppler | 5/4/2019 | 17/6/2026 | An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc. | |
| Modificada | Alta (8.8) | 2.7% | — | Freedesktop Poppler | 5/4/2019 | 17/6/2026 | An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. | |
| Modificada | Media (6.5) | 2.5% | — | Freedesktop Poppler | 5/4/2019 | 17/6/2026 | An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc. | |
| Modificada | Media (6.5) | 2.4% | — | Freedesktop PopplerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 21/3/2019 | 17/6/2026 | PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary. | |
| Modificada | Crítica (9.8) | 3.5% | — | Freedesktop PopplerFedoraproject FedoraDebian Linux | 8/3/2019 | 17/6/2026 | Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. | |
| Modificada | Alta (8.8) | 1.8% | — | Freedesktop Poppler | 1/3/2019 | 17/6/2026 | An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified… |