CVE-2008-2950
Status: ModifiedHigh (7.5)—💥 Exploit
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 15%
- Percentile among all scored CVEs: 97
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Poppler 0.8.4 - libpoppler Uninitialized pointer Code Execution (7/8/2008)
Affected technologies (1)
CWEs
- CWE-94
References
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
- http://secunia.com/advisories/30963
- http://secunia.com/advisories/31002
- http://secunia.com/advisories/31167
- http://secunia.com/advisories/31267
- http://secunia.com/advisories/31405
- http://security.gentoo.org/glsa/glsa-200807-04.xml
- http://securityreason.com/securityalert/3977
- http://wiki.rpath.com/Advisories:rPSA-2008-0223
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:146
- http://www.ocert.org/advisories/ocert-2008-007.html
- http://www.securityfocus.com/archive/1/493980/100/0/threaded
- http://www.securityfocus.com/archive/1/494142/100/0/threaded
- http://www.securityfocus.com/bid/30107
- http://www.securitytracker.com/id?1020435
- http://www.ubuntu.com/usn/usn-631-1
- http://www.vupen.com/english/advisories/2008/2024/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43619
- https://www.exploit-db.com/exploits/6032
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00161.html
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
- http://secunia.com/advisories/30963
- http://secunia.com/advisories/31002
- http://secunia.com/advisories/31167
- http://secunia.com/advisories/31267
- http://secunia.com/advisories/31405
- http://security.gentoo.org/glsa/glsa-200807-04.xml
- http://securityreason.com/securityalert/3977
- http://wiki.rpath.com/Advisories:rPSA-2008-0223
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:146
- http://www.ocert.org/advisories/ocert-2008-007.html
- http://www.securityfocus.com/archive/1/493980/100/0/threaded
- http://www.securityfocus.com/archive/1/494142/100/0/threaded
- http://www.securityfocus.com/bid/30107
- http://www.securitytracker.com/id?1020435
- http://www.ubuntu.com/usn/usn-631-1
- http://www.vupen.com/english/advisories/2008/2024/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43619
- https://www.exploit-db.com/exploits/6032
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00161.html
Raw JSON (NVD)
Show
{
"id": "CVE-2008-2950",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-07-07T23:41:00.000",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/30963",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31002",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31167",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31267",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31405",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200807-04.xml",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3977",
"source": "cve@mitre.org"
},
{
"url": "http://wiki.rpath.com/Advisories:rPSA-2008-0223",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:146",
"source": "cve@mitre.org"
},
{
"url": "http://www.ocert.org/advisories/ocert-2008-007.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/493980/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/494142/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/30107",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1020435",
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/usn-631-1",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2024/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43619",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/6032",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00161.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/30963",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31002",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31167",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31267",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31405",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200807-04.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3977",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wiki.rpath.com/Advisories:rPSA-2008-0223",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:146",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ocert.org/advisories/ocert-2008-007.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/493980/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/494142/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/30107",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020435",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/usn-631-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2024/references",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43619",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/6032",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00161.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document."
},
{
"lang": "es",
"value": "El destructor Page de Page.cc en libpoppler de Poppler 0.8.4 y anteriores, elimina el objeto pageWidgets incluso si éste no ha sido iniciado por un constructor Page, esto permite a atacantes remotos ejecutar código de su elección mediante un documento PDF manipulado."
}
],
"lastModified": "2026-06-16T22:54:48.340",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:poppler:poppler:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5739C603-4976-48C9-B28F-9E3FD9D3E2A9",
"versionEndIncluding": "0.8.4"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Not vulnerable. This issue did not affect the versions of poppler as shipped with Red Hat Enterprise Linux 5, or other PDF parsing applications derived from the xpdf code as shipped in Red Hat Enterprise Linux 2.1, 3, 4, or 5.",
"lastModified": "2008-07-08T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}