Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 5.4% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data. | |
| Modificada | Media (6.8) | 5.5% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (6.8) | 5.5% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (4.3) | 3.8% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read. | |
| Modificada | Media (6.8) | 5.4% | — | Apple CupsFoolabs XpdfGlyphandcog Xpdfreader | 23/4/2009 | 16/6/2026 | Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments. | |
| Modificada | Media (4.3) | 2.3% | — | Foolabs XpdfGlyphandcog XpdfreaderPopplerApple Cups | 23/4/2009 | 16/6/2026 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory. | |
| Modificada | Media (4.3) | 2.6% | — | Foolabs XpdfGlyphandcog XpdfreaderApple Cups | 23/4/2009 | 16/6/2026 | Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3)… | |
| Modificada | Media (4.3) | 2.8% | — | Foolabs XpdfGlyphandcog XpdfreaderApple Cups | 23/4/2009 | 16/6/2026 | Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. | |
| Modificada | Media (6.9) | 0.40% | — | Foolabs XpdfGlyphandcog Xpdfreader | 9/4/2009 | 16/6/2026 | Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library. | |
| Modificada | Media (6.8) | 8.6% | — | Apple CupsFreedesktop PopplerGpdf Project GpdfXpdfreader Xpdf+2 | 30/7/2007 | 16/6/2026 | Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based… |