Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

180 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.75%—Xpdfreader Xpdf18/5/202217/6/2026
There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
ModificadaMedia (5.5)0.84%—Xpdfreader Xpdf16/5/202217/6/2026
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.
ModificadaAlta (7.8)1.6%💥 PoCXpdfreader Xpdf9/5/202217/6/2026
There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service…
ModificadaMedia (5.5)1.0%—Xpdfreader Xpdf25/4/202217/6/2026
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.
AnalizadaAlta (7.8)76%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MAC OS XApple Macos+324/8/202117/6/2026
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…
ModificadaAlta (7.5)2.1%—Xpdfreader XpdfFedoraproject Fedora26/12/202017/6/2026
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
ModificadaMedia (5.5)1.0%—Xpdfreader XpdfFedoraproject Fedora21/11/202017/6/2026
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char…
ModificadaAlta (7.8)1.1%—Xpdfreader Xpdf3/9/202017/6/2026
There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
ModificadaAlta (7.8)1.1%—Xpdfreader Xpdf3/9/202017/6/2026
There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other…
ModificadaAlta (7.8)2.9%—Freedesktop PopplerXpdfreader XpdfRedhat Enterprise LinuxOpensuse9/1/202016/6/2026
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
ModificadaMedia (5.5)0.85%—Xpdfreader Xpdf30/10/201916/6/2026
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
ModificadaMedia (5.5)1.1%—Xpdfreader Xpdf30/10/201916/6/2026
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
ModificadaMedia (5.5)1.4%—Glyphandcog Xpdfreader1/10/201917/6/2026
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
ModificadaMedia (5.5)0.86%—Glyphandcog Xpdf27/9/201917/6/2026
Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.
ModificadaAlta (7.8)1.1%—Glyphandcog Xpdfreader8/9/201917/6/2026
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or…
ModificadaMedia (5.5)0.91%—Glyphandcog Xpdfreader6/9/201917/6/2026
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
ModificadaMedia (5.5)0.87%—Glyphandcog Xpdfreader3/9/201917/6/2026
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.
ModificadaMedia (5.5)1.1%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.
ModificadaAlta (7.8)1.0%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
ModificadaMedia (5.5)1.1%—Glyphandcog Xpdfreader4/7/201917/6/2026
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.
Orbitaley — Vulnerabilidades