Skip to main content

Vendor archive

freedesktop CVEs

Beta · best-effort

150 CVEs tagged to vendor freedesktop4 Critical, 48 High, 79 Medium, 19 Low, 0 Unrated.

CVE-2018-13988

Published Jul 25, 2018

Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can r…

CVSS 6.5 · Medium

CVE-2018-14036

Published Jul 13, 2018

Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14977

Published Oct 2, 2017

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14976

Published Oct 2, 2017

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14975

Published Oct 2, 2017

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14929

Published Sep 30, 2017

In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14927

Published Sep 30, 2017

In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14617

Published Sep 20, 2017

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14520

Published Sep 17, 2017

In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14519

Published Sep 17, 2017

In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14518

Published Sep 17, 2017

In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14517

Published Sep 17, 2017

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2820

Published Jul 12, 2017

An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2818

Published Jul 12, 2017

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color comp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2814

Published Jul 12, 2017

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9865

Published Jun 25, 2017

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) v…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 150 CVEsPage 4 of 6