Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.78% | — | Xpdfreader Xpdf | 14/3/2018 | 17/6/2026 | The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml. | |
| Modificada | Media (5.5) | 0.78% | — | Xpdfreader Xpdf | 14/3/2018 | 17/6/2026 | The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml. | |
| Modificada | Alta (7.8) | 0.92% | — | Xpdfreader Xpdf | 14/3/2018 | 17/6/2026 | The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml. | |
| Modificada | Media (5.5) | 0.78% | — | Xpdfreader Xpdf | 24/2/2018 | 17/6/2026 | An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |
| Modificada | Media (5.5) | 0.78% | — | Xpdfreader Xpdf | 24/2/2018 | 17/6/2026 | A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |
| Modificada | Media (5.5) | 0.90% | — | Xpdfreader Xpdf | 24/2/2018 | 17/6/2026 | Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. | |
| Modificada | Media (5.5) | 0.79% | — | Xpdfreader Xpdf | 24/2/2018 | 17/6/2026 | A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |
| Modificada | Media (5.5) | 0.82% | — | Xpdfreader Xpdf | 15/2/2018 | 17/6/2026 | An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. | |
| Modificada | Media (5.5) | 0.83% | — | Xpdfreader Xpdf | 15/2/2018 | 17/6/2026 | An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. | |
| Modificada | Media (5.5) | 0.78% | — | Xpdfreader Xpdf | 15/2/2018 | 17/6/2026 | A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. | |
| Modificada | Media (4.3) | 5.4% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a… | |
| Modificada | Media (4.3) | 5.4% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than… | |
| Modificada | Media (4.3) | 10% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764. | |
| Modificada | Media (6.8) | 13% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf. | |
| Modificada | Media (6.8) | 3.6% | — | PopplerFoolabs XpdfGlyphandcog XpdfreaderKdegraphics | 5/11/2010 | 16/6/2026 | The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a… | |
| Modificada | Alta (7.5) | 2.8% | — | Apple CupsFreedesktop PopplerXpdfreader XpdfFedoraproject Fedora+7 | 5/11/2010 | 16/6/2026 | The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference. | |
| Modificada | Media (4.3) | 4.7% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or… | |
| Modificada | Alta (9.3) | 10% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 8.6% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 8.7% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that… | |
| Modificada | Alta (9.3) | 8.6% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE:… | |
| Modificada | Alta (10) | 3.6% | — | Foolabs XpdfGlyphandcog Xpdfreader | 23/4/2009 | 16/6/2026 | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn." | |
| Modificada | Media (4.3) | 3.8% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file. | |
| Modificada | Alta (7.5) | 7.3% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (4.3) | 3.8% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference. |