Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

135 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.43%—Xpdfreader Xpdf30/9/202217/6/2026
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
ModificadaAlta (7.8)0.47%—Xpdfreader Xpdf29/9/202217/6/2026
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
ModificadaAlta (7.8)0.43%—Xpdfreader Xpdf21/9/202217/6/2026
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
ModificadaMedia (5.5)0.41%—Xpdfreader Xpdf15/9/202217/6/2026
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
ModificadaMedia (5.5)0.34%—Xpdfreader Xpdf30/8/202217/6/2026
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
ModificadaAlta (7.8)0.31%—Glyphandcog Xpdfreader30/8/202217/6/2026
Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
ModificadaAlta (7.8)0.31%—Glyphandcog Xpdfreader30/8/202217/6/2026
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
ModificadaAlta (7.8)0.34%—Xpdfreader XpdfFreedesktop Poppler22/8/202217/6/2026
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple…
ModificadaAlta (7.8)1.1%—Xpdfreader Xpdf28/6/202217/6/2026
XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
ModificadaMedia (5.5)0.74%—Xpdfreader Xpdf18/5/202217/6/2026
There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
ModificadaMedia (5.5)0.84%—Xpdfreader Xpdf16/5/202217/6/2026
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.
ModificadaAlta (7.8)1.6%—Xpdfreader Xpdf9/5/202217/6/2026
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service…
ModificadaMedia (5.5)1.0%—Xpdfreader Xpdf25/4/202217/6/2026
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.
AnalizadaAlta (7.8)76%⚠ Explotación activaApple IpadosApple Iphone OSApple MAC OS XApple Macos+324/8/202117/6/2026
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…
ModificadaAlta (7.5)2.1%—Xpdfreader XpdfFedoraproject Fedora26/12/202017/6/2026
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
ModificadaMedia (5.5)1.0%—Xpdfreader XpdfFedoraproject Fedora21/11/202017/6/2026
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char…
ModificadaAlta (7.8)1.1%—Xpdfreader Xpdf3/9/202017/6/2026
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
ModificadaAlta (7.8)1.1%—Xpdfreader Xpdf3/9/202017/6/2026
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other…
ModificadaAlta (7.8)2.9%—Freedesktop PopplerXpdfreader XpdfRedhat Enterprise LinuxOpensuse9/1/202016/6/2026
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
ModificadaMedia (5.5)0.85%—Xpdfreader Xpdf30/10/201916/6/2026
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
ModificadaMedia (5.5)1.1%—Xpdfreader Xpdf30/10/201916/6/2026
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
ModificadaMedia (5.5)1.4%—Glyphandcog Xpdfreader1/10/201917/6/2026
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
ModificadaAlta (7.8)1.1%—Glyphandcog Xpdfreader8/9/201917/6/2026
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or…
ModificadaMedia (5.5)0.91%—Glyphandcog Xpdfreader6/9/201917/6/2026
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
ModificadaMedia (5.5)0.87%—Glyphandcog Xpdfreader3/9/201917/6/2026
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.