Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Freedesktop PopplerDebian Linux22/8/202317/6/2026
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
ModificadaMedia (6.5)0.65%—Freedesktop Poppler22/8/202317/6/2026
Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.
ModificadaMedia (5.5)0.53%—Freedesktop Poppler11/8/202317/6/2026
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.
ModificadaMedia (6.5)1.2%—Freedesktop Poppler11/8/202317/6/2026
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.
ModificadaMedia (5.5)0.90%—Freedesktop Poppler31/7/202317/6/2026
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
ModificadaAlta (7.8)0.63%—Freedesktop PopplerDebian LinuxFedoraproject Fedora30/8/202217/6/2026
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171…
ModificadaAlta (7.8)0.34%—Xpdfreader XpdfFreedesktop Poppler22/8/202217/6/2026
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple…
ModificadaMedia (6.5)1.6%—Freedesktop PopplerFedoraproject FedoraDebian Linux5/5/202217/6/2026
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
AnalizadaAlta (7.8)76%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MAC OS XApple Macos+324/8/202117/6/2026
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…
ModificadaAlta (7.8)0.87%—Freedesktop Poppler25/12/202017/6/2026
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability.…
ModificadaAlta (7.5)2.2%—Freedesktop PopplerRedhat Enterprise LinuxDebian Linux3/12/202017/6/2026
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.
ModificadaAlta (7.8)2.9%—Freedesktop PopplerXpdfreader XpdfRedhat Enterprise LinuxOpensuse9/1/202016/6/2026
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
ModificadaAlta (7.8)1.2%—Freedesktop PopplerDebian Linux13/11/201916/6/2026
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
ModificadaMedia (6.5)1.8%—Freedesktop PopplerDebian Linux13/11/201916/6/2026
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
ModificadaAlta (8.8)1.9%—Freedesktop Poppler5/9/201917/6/2026
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
ModificadaAlta (7.5)2.7%—Freedesktop PopplerCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+11/8/201917/6/2026
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
ModificadaMedia (6.5)1.9%—Freedesktop PopplerDebian LinuxFedoraproject FedoraRedhat Enterprise Linux+322/7/201917/6/2026
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.
ModificadaAlta (8.8)2.1%—Freedesktop Poppler23/5/201917/6/2026
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.
ModificadaMedia (6.5)1.8%—Freedesktop PopplerFedoraproject Fedora8/4/201917/6/2026
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
ModificadaMedia (6.5)2.6%—Freedesktop Poppler5/4/201917/6/2026
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
ModificadaAlta (8.8)2.7%—Freedesktop Poppler5/4/201917/6/2026
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.
ModificadaMedia (6.5)2.5%—Freedesktop Poppler5/4/201917/6/2026
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
ModificadaMedia (6.5)2.4%—Freedesktop PopplerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+421/3/201917/6/2026
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
ModificadaCrítica (9.8)3.5%—Freedesktop PopplerFedoraproject FedoraDebian Linux8/3/201917/6/2026
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
ModificadaAlta (8.8)1.8%—Freedesktop Poppler1/3/201917/6/2026
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified…
Orbitaley — Vulnerabilidades