Freedesktop
Freedesktop Poppler: vulnerabilidades y CVE
Freedesktop Poppler tiene 94 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE94
Últimos 12 meses6
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-30860 | Alta (7.8) | 76% | ⚠ Explotación activa | 24 ago 2021 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102621 | Baja (1.9) | 0.11% | — | 29 sept 2026 | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be… |
| CVE-2026-102620 | Baja (1.9) | 0.11% | — | 29 sept 2026 | A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can… |
| CVE-2026-93314 | Baja (2.1) | 0.43% | — | 18 sept 2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer… |
| CVE-2026-93313 | Baja (2.1) | 0.43% | — | 18 sept 2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The… |
| CVE-2026-93312 | Baja (2.1) | 0.59% | — | 17 sept 2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the… |
| CVE-2026-93311 | Baja (2.1) | 0.56% | — | 17 sept 2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the… |
| CVE-2025-50420 | Media (6.5) | 0.32% | — | 4 ago 2025 | An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS). |
| CVE-2025-52886 | Media (5.5) | 0.42% | — | 2 jul 2025 | Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a… |
| CVE-2025-43903 | Baja (3.3) | 0.11% | — | 18 abr 2025 | NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries. |
| CVE-2025-32365 | Alta (7.1) | 0.25% | — | 5 abr 2025 | Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check. |
| CVE-2025-32364 | Media (5.5) | 0.27% | — | 5 abr 2025 | A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN. |
| CVE-2024-56378 | Media (4.3) | 0.62% | — | 23 dic 2024 | libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc. |
| CVE-2024-6239 | Alta (7.5) | 0.78% | — | 21 jun 2024 | A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a… |
| CVE-2022-38349 | Media (6.5) | 1.1% | — | 22 ago 2023 | An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file. |
| CVE-2022-37052 | Media (6.5) | 1.1% | — | 22 ago 2023 | A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject. |
| CVE-2022-37051 | Media (6.5) | 1.1% | — | 22 ago 2023 | An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file. |
| CVE-2022-37050 | Media (6.5) | 1.1% | — | 22 ago 2023 | In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog… |
| CVE-2020-23804 | Alta (7.5) | 1.2% | — | 22 ago 2023 | Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input. |
| CVE-2020-18839 | Media (6.5) | 0.65% | — | 22 ago 2023 | Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service. |
| CVE-2020-36024 | Media (5.5) | 0.53% | — | 11 ago 2023 | An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function. |
| CVE-2020-36023 | Media (6.5) | 1.2% | — | 11 ago 2023 | An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function. |
| CVE-2023-34872 | Media (5.5) | 0.90% | — | 31 jul 2023 | A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open. |
| CVE-2022-38784 | Alta (7.8) | 0.63% | — | 30 ago 2022 | Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash… |
| CVE-2022-38171 | Alta (7.8) | 0.34% | — | 22 ago 2022 | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the… |
| CVE-2022-27337 | Media (6.5) | 1.6% | — | 5 may 2022 | A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. |
| CVE-2021-30860 | Alta (7.8) | 76% | ⚠ Explotación activa | 24 ago 2021 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted… |
| CVE-2020-35702 | Alta (7.8) | 0.87% | — | 25 dic 2020 | DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December… |
| CVE-2020-27778 | Alta (7.5) | 2.2% | — | 3 dic 2020 | A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash… |
| CVE-2012-2142 | Alta (7.8) | 2.9% | — | 9 ene 2020 | The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. |
| CVE-2010-4654 | Alta (7.8) | 1.2% | — | 13 nov 2019 | poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.