Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.1% | — | Glyphandcog Xpdfreader | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. | |
| Modificada | Media (5.5) | 4.6% | 💥 PoC | Glyphandcog Xpdfreader | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646. | |
| Modificada | Media (5.5) | 1.2% | — | Glyphandcog Xpdfreader | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to… | |
| Modificada | Media (5.5) | 1.1% | — | Glyphandcog XpdfreaderFedoraproject Fedora | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. | |
| Modificada | Alta (7.8) | 1.1% | — | Glyphandcog XpdfreaderFedoraproject Fedora | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows… | |
| Modificada | Alta (7.8) | 1.1% | — | Glyphandcog XpdfreaderFedoraproject Fedora | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or… | |
| Modificada | Alta (7.8) | 1.2% | — | Glyphandcog XpdfreaderFedoraproject Fedora | 4/7/2019 | 17/6/2026 | In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an… | |
| Modificada | Media (5.5) | 1.2% | — | Glyphandcog Xpdfreader | 25/6/2019 | 17/6/2026 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated. | |
| Modificada | Alta (7.8) | 1.2% | — | Glyphandcog XpdfreaderFedoraproject Fedora | 25/6/2019 | 17/6/2026 | In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause… | |
| Modificada | Alta (7.1) | 1.3% | — | Glyphandcog Xpdfreader | 2/6/2019 | 17/6/2026 | There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service. | |
| Modificada | Alta (7.1) | 1.3% | — | Glyphandcog Xpdfreader | 31/5/2019 | 17/6/2026 | A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause… | |
| Modificada | Alta (7.1) | 1.1% | — | Glyphandcog Xpdfreader | 27/5/2019 | 17/6/2026 | A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content. | |
| Modificada | Media (5.5) | 0.87% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case. | |
| Modificada | Media (5.5) | 0.87% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits. | |
| Modificada | Media (5.5) | 0.87% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters. | |
| Modificada | Media (5.5) | 0.90% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case. | |
| Modificada | Media (5.5) | 0.88% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc. | |
| Modificada | Media (5.5) | 0.90% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps. | |
| Modificada | Media (5.5) | 0.87% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters. | |
| Modificada | Media (5.5) | 0.90% | — | Xpdfreader Xpdf | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes. | |
| Modificada | Media (5.5) | 1.1% | — | Xpdfreader XpdfDebian LinuxCanonical Ubuntu Linux | 25/3/2019 | 17/6/2026 | An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case. | |
| Modificada | Alta (7.8) | 1.2% | — | Pdfalto Project PdfaltoXpdfreader Xpdf | 21/3/2019 | 17/6/2026 | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly… | |
| Modificada | Alta (7.8) | 1.1% | — | Xpdfreader Xpdf | 21/3/2019 | 17/6/2026 | There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified… | |
| Modificada | Alta (7.8) | 1.2% | — | Glyphandcog Xpdfreader | 6/3/2019 | 17/6/2026 | There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other… | |
| Modificada | Alta (7.8) | 1.2% | — | Glyphandcog Xpdfreader | 6/3/2019 | 17/6/2026 | There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. |