Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.8% | — | Artifex MupdfDebian Linux | 24/1/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex MupdfDebian Linux | 24/1/2018 | 17/6/2026 | In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file. | |
| Modificada | Alta (7.8) | 2.7% | — | Artifex Mupdf | 22/1/2018 | 17/6/2026 | Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex MupdfDebian Linux | 14/1/2018 | 17/6/2026 | In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file. | |
| Modificada | Alta (7.8) | 1.6% | — | Artifex MupdfDebian Linux | 27/12/2017 | 17/6/2026 | pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document. | |
| Modificada | Alta (7.8) | 1.00% | — | Artifex Mupdf | 18/10/2017 | 17/6/2026 | An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11. | |
| Modificada | Alta (7.8) | 1.3% | — | Artifex Mupdf | 16/10/2017 | 17/6/2026 | The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a register, which allows remote attackers to cause a denial of service (Fitz fz_drop_imp use-after-free and application crash) or possibly have unspecified other impact via a… | |
| Modificada | Alta (7.8) | 1.3% | — | Artifex Mupdf | 22/9/2017 | 17/6/2026 | Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016cb4f" on Windows. This occurs because of mishandling of XML tag name comparisons. | |
| Modificada | Alta (7.8) | 1.9% | — | Artifex Mupdf | 22/9/2017 | 17/6/2026 | Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in… | |
| Modificada | Alta (7.8) | 1.3% | — | Artifex Mupdf | 22/9/2017 | 17/6/2026 | Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not… | |
| Modificada | Media (4.3) | 1.4% | — | Artifex Mupdf | 3/4/2017 | 17/6/2026 | The count_entries function in pdf-layer.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted PDF document. | |
| Modificada | Media (5.3) | 1.4% | — | Artifex Mupdf | 26/3/2017 | 17/6/2026 | Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex MupdfDebian Linux | 16/3/2017 | 17/6/2026 | Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. | |
| Modificada | Media (5.5) | 1.5% | — | Artifex MupdfDebian Linux | 16/3/2017 | 17/6/2026 | Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. | |
| Modificada | Alta (7.8) | 6.8% | 💥 Exploit | Artifex MupdfDebian Linux | 15/3/2017 | 17/6/2026 | Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex Mupdf | 15/2/2017 | 17/6/2026 | The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file. | |
| Modificada | Media (5.5) | 1.7% | — | Artifex Mupdf | 15/2/2017 | 17/6/2026 | Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c in MuPDF 1.10a allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted image. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Artifex MupdfDebian Linux | 15/2/2017 | 17/6/2026 | An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected. | |
| Modificada | Crítica (9.8) | 3.8% | — | Debian LinuxArtifex Mupdf | 22/9/2016 | 17/6/2026 | Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array. | |
| Modificada | Media (5.5) | 1.6% | — | Artifex MupdfOpensuse LeapOpensuse | 22/9/2016 | 17/6/2026 | Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Artifex Mupdf | 3/3/2014 | 17/6/2026 | Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element. | |
| Modificada | Alta (9.3) | 3.8% | — | Artifex Mupdf | 13/5/2011 | 16/6/2026 | Stack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attackers to execute arbitrary code via a crafted web site. |