Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.75% | — | Xpdfreader Xpdf | 18/5/2022 | 17/6/2026 | There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03. | |
| Modificada | Media (5.5) | 0.84% | — | Xpdfreader Xpdf | 16/5/2022 | 17/6/2026 | xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option. | |
| Modificada | Alta (7.8) | 1.6% | 💥 PoC | Xpdfreader Xpdf | 9/5/2022 | 17/6/2026 | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service… | |
| Modificada | Media (5.5) | 1.0% | — | Xpdfreader Xpdf | 25/4/2022 | 17/6/2026 | xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary. | |
| Analizada | Alta (7.8) | 76% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+3 | 24/8/2021 | 17/6/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been… | |
| Modificada | Alta (7.5) | 2.1% | — | Xpdfreader XpdfFedoraproject Fedora | 26/12/2020 | 17/6/2026 | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function. | |
| Modificada | Media (5.5) | 1.0% | — | Xpdfreader XpdfFedoraproject Fedora | 21/11/2020 | 17/6/2026 | In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char… | |
| Modificada | Alta (7.8) | 1.1% | — | Xpdfreader Xpdf | 3/9/2020 | 17/6/2026 | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 1.1% | — | Xpdfreader Xpdf | 3/9/2020 | 17/6/2026 | There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other… | |
| Modificada | Alta (7.8) | 2.9% | — | Freedesktop PopplerXpdfreader XpdfRedhat Enterprise LinuxOpensuse | 9/1/2020 | 16/6/2026 | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5.5) | 0.85% | — | Xpdfreader Xpdf | 30/10/2019 | 16/6/2026 | In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers. | |
| Modificada | Media (5.5) | 1.1% | — | Xpdfreader Xpdf | 30/10/2019 | 16/6/2026 | xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects. | |
| Modificada | Media (5.5) | 1.4% | — | Glyphandcog Xpdfreader | 1/10/2019 | 17/6/2026 | Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. | |
| Modificada | Media (5.5) | 0.86% | — | Glyphandcog Xpdf | 27/9/2019 | 17/6/2026 | Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877. | |
| Modificada | Alta (7.8) | 1.1% | — | Glyphandcog Xpdfreader | 8/9/2019 | 17/6/2026 | In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or… | |
| Modificada | Media (5.5) | 0.91% | — | Glyphandcog Xpdfreader | 6/9/2019 | 17/6/2026 | Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc. | |
| Modificada | Media (5.5) | 0.87% | — | Glyphandcog Xpdfreader | 3/9/2019 | 17/6/2026 | Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002. | |
| Modificada | Media (5.5) | 0.95% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read. | |
| Modificada | Media (5.5) | 0.95% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2. | |
| Modificada | Media (5.5) | 1.1% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1. | |
| Modificada | Media (5.5) | 0.95% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3. | |
| Modificada | Media (5.5) | 0.95% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2. | |
| Modificada | Media (5.5) | 0.95% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case. | |
| Modificada | Alta (7.8) | 1.0% | — | Glyphandcog Xpdfreader | 27/7/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case. | |
| Modificada | Media (5.5) | 1.1% | — | Glyphandcog Xpdfreader | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure. |