Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.82% | — | Xpdfreader Xpdf | 15/2/2018 | 17/6/2026 | An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. | |
| Modificada | Media (5.5) | 0.83% | — | Xpdfreader Xpdf | 15/2/2018 | 17/6/2026 | An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. | |
| Modificada | Media (5.5) | 0.78% | — | Xpdfreader Xpdf | 15/2/2018 | 17/6/2026 | A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. | |
| Modificada | Media (5.3) | 1.4% | — | Glyphandcog XpdfDebian Linux | 30/1/2018 | 16/6/2026 | zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name. | |
| Modificada | Media (4.3) | 5.4% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a… | |
| Modificada | Media (4.3) | 5.4% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than… | |
| Modificada | Media (4.3) | 10% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764. | |
| Modificada | Media (6.8) | 13% | — | T1libFoolabs XpdfGlyphandcog Xpdfreader | 31/3/2011 | 16/6/2026 | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf. | |
| Modificada | Media (6.8) | 3.6% | — | PopplerFoolabs XpdfGlyphandcog XpdfreaderKdegraphics | 5/11/2010 | 16/6/2026 | The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a… | |
| Modificada | Alta (7.5) | 2.8% | — | Apple CupsFreedesktop PopplerXpdfreader XpdfFedoraproject Fedora+7 | 5/11/2010 | 16/6/2026 | The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference. | |
| Modificada | Alta (9.3) | 3.8% | — | Gnome GpdfKdegraphicsKDE KpdfXpdf | 21/12/2009 | 16/6/2026 | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font… | |
| Modificada | Media (4.3) | 4.7% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or… | |
| Modificada | Alta (9.3) | 10% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 8.6% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 8.7% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that… | |
| Modificada | Alta (9.3) | 8.6% | — | Foolabs XpdfGlyphandcog XpdfreaderPoppler | 21/10/2009 | 16/6/2026 | Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE:… | |
| Modificada | Alta (10) | 3.6% | — | Foolabs XpdfGlyphandcog Xpdfreader | 23/4/2009 | 16/6/2026 | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn." | |
| Modificada | Media (4.3) | 3.8% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file. | |
| Modificada | Alta (7.5) | 7.3% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (4.3) | 3.8% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference. | |
| Modificada | Media (6.8) | 5.4% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data. | |
| Modificada | Media (6.8) | 5.5% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (6.8) | 5.5% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (4.3) | 3.8% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read. | |
| Modificada | Media (6.8) | 5.4% | — | Apple CupsFoolabs XpdfGlyphandcog Xpdfreader | 23/4/2009 | 16/6/2026 | Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments. |