Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

135 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.
ModificadaMedia (5.5)1.1%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.
ModificadaMedia (5.5)0.95%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.
ModificadaAlta (7.8)1.0%—Glyphandcog Xpdfreader27/7/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
ModificadaMedia (5.5)1.1%—Glyphandcog Xpdfreader4/7/201917/6/2026
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.
ModificadaAlta (7.8)1.1%—Glyphandcog Xpdfreader4/7/201917/6/2026
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.
ModificadaMedia (5.5)4.6%—Glyphandcog Xpdfreader4/7/201917/6/2026
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
ModificadaMedia (5.5)1.2%—Glyphandcog Xpdfreader4/7/201917/6/2026
In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to…
ModificadaMedia (5.5)1.1%—Glyphandcog XpdfreaderFedoraproject Fedora4/7/201917/6/2026
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.
ModificadaAlta (7.8)1.1%—Glyphandcog XpdfreaderFedoraproject Fedora4/7/201917/6/2026
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows…
ModificadaAlta (7.8)1.1%—Glyphandcog XpdfreaderFedoraproject Fedora4/7/201917/6/2026
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or…
ModificadaAlta (7.8)1.2%—Glyphandcog XpdfreaderFedoraproject Fedora4/7/201917/6/2026
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an…
ModificadaMedia (5.5)1.2%—Glyphandcog Xpdfreader25/6/201917/6/2026
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.
ModificadaAlta (7.8)1.2%—Glyphandcog XpdfreaderFedoraproject Fedora25/6/201917/6/2026
In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause…
ModificadaAlta (7.1)1.3%—Glyphandcog Xpdfreader2/6/201917/6/2026
There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service.
ModificadaAlta (7.1)1.3%—Glyphandcog Xpdfreader31/5/201917/6/2026
A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause…
ModificadaAlta (7.1)1.1%—Glyphandcog Xpdfreader27/5/201917/6/2026
A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.
ModificadaMedia (5.5)0.87%—Xpdfreader Xpdf25/3/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.
ModificadaMedia (5.5)0.87%—Xpdfreader Xpdf25/3/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.
ModificadaMedia (5.5)0.87%—Xpdfreader Xpdf25/3/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.
ModificadaMedia (5.5)0.90%—Xpdfreader Xpdf25/3/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.
ModificadaMedia (5.5)0.88%—Xpdfreader Xpdf25/3/201917/6/2026
An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.