Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.43% | — | Xpdfreader Xpdf | 30/9/2022 | 17/6/2026 | An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc. | |
| Modificada | Alta (7.8) | 0.47% | — | Xpdfreader Xpdf | 29/9/2022 | 17/6/2026 | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 0.43% | — | Xpdfreader Xpdf | 21/9/2022 | 17/6/2026 | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. | |
| Modificada | Media (5.5) | 0.41% | — | Xpdfreader Xpdf | 15/9/2022 | 17/6/2026 | XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc. | |
| Modificada | Media (5.5) | 0.34% | — | Xpdfreader Xpdf | 30/8/2022 | 17/6/2026 | XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538. | |
| Modificada | Alta (7.8) | 0.31% | — | Glyphandcog Xpdfreader | 30/8/2022 | 17/6/2026 | Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. | |
| Modificada | Alta (7.8) | 0.31% | — | Glyphandcog Xpdfreader | 30/8/2022 | 17/6/2026 | In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc. | |
| Modificada | Alta (7.8) | 0.34% | — | Xpdfreader XpdfFreedesktop Poppler | 22/8/2022 | 17/6/2026 | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple… | |
| Modificada | Alta (7.8) | 1.1% | — | Xpdfreader Xpdf | 28/6/2022 | 17/6/2026 | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. | |
| Modificada | Media (5.5) | 0.74% | — | Xpdfreader Xpdf | 18/5/2022 | 17/6/2026 | There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03. | |
| Modificada | Media (5.5) | 0.84% | — | Xpdfreader Xpdf | 16/5/2022 | 17/6/2026 | xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option. | |
| Modificada | Alta (7.8) | 1.6% | — | Xpdfreader Xpdf | 9/5/2022 | 17/6/2026 | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service… | |
| Modificada | Media (5.5) | 1.0% | — | Xpdfreader Xpdf | 25/4/2022 | 17/6/2026 | xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary. | |
| Analizada | Alta (7.8) | 76% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+3 | 24/8/2021 | 17/6/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been… | |
| Modificada | Alta (7.5) | 2.1% | — | Xpdfreader XpdfFedoraproject Fedora | 26/12/2020 | 17/6/2026 | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function. | |
| Modificada | Media (5.5) | 1.0% | — | Xpdfreader XpdfFedoraproject Fedora | 21/11/2020 | 17/6/2026 | In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char… | |
| Modificada | Alta (7.8) | 1.1% | — | Xpdfreader Xpdf | 3/9/2020 | 17/6/2026 | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 1.1% | — | Xpdfreader Xpdf | 3/9/2020 | 17/6/2026 | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other… | |
| Modificada | Alta (7.8) | 2.9% | — | Freedesktop PopplerXpdfreader XpdfRedhat Enterprise LinuxOpensuse | 9/1/2020 | 16/6/2026 | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5.5) | 0.85% | — | Xpdfreader Xpdf | 30/10/2019 | 16/6/2026 | In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers. | |
| Modificada | Media (5.5) | 1.1% | — | Xpdfreader Xpdf | 30/10/2019 | 16/6/2026 | xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects. | |
| Modificada | Media (5.5) | 1.4% | — | Glyphandcog Xpdfreader | 1/10/2019 | 17/6/2026 | Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. | |
| Modificada | Alta (7.8) | 1.1% | — | Glyphandcog Xpdfreader | 8/9/2019 | 17/6/2026 | In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or… | |
| Modificada | Media (5.5) | 0.91% | — | Glyphandcog Xpdfreader | 6/9/2019 | 17/6/2026 | Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc. | |
| Modificada | Media (5.5) | 0.87% | — | Glyphandcog Xpdfreader | 3/9/2019 | 17/6/2026 | Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002. |