Skip to main content

Vendor archive

freedesktop CVEs

Beta · best-effort

150 CVEs tagged to vendor freedesktop4 Critical, 48 High, 79 Medium, 19 Low, 0 Unrated.

CVE-2019-12749

Published Jun 11, 2019

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon),…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12293

Published May 23, 2019

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10873

Published Apr 5, 2019

An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10872

Published Apr 5, 2019

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10871

Published Apr 5, 2019

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9545

Published Mar 1, 2019

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9543

Published Mar 1, 2019

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7310

Published Feb 3, 2019

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of servic…

CVSS 7.8 · High

CVE-2018-20662

Published Jan 3, 2019

In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDF…

CVSS 6.5 · Medium

CVE-2018-20650

Published Jan 1, 2019

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use…

CVSS 6.5 · Medium

CVE-2018-20551

Published Dec 28, 2018

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18897

Published Nov 2, 2018

An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.

CVSS 6.5 · Medium
Showing 51-75 of 150 CVEsPage 3 of 6