Skip to main content

Vendor/product archive

glyphandcog / xpdfreader CVEs

Beta · best-effort

53 CVEs tagged to glyphandcog / xpdfreader5 Critical, 17 High, 31 Medium, 0 Low, 0 Unrated.

CVE-2022-24106

Published Aug 30, 2022

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-relate…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17064

Published Oct 1, 2019

Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16115

Published Sep 8, 2019

In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be trigg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16088

Published Sep 6, 2019

Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15860

Published Sep 3, 2019

Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14294

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14293

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14292

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14291

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14290

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14289

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14288

Published Jul 27, 2019

An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13291

Published Jul 4, 2019

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF docu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13289

Published Jul 4, 2019

In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13288

Published Jul 4, 2019

In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13287

Published Jul 4, 2019

In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by se…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12958

Published Jun 25, 2019

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array ele…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12515

Published Jun 2, 2019

There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PD…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 53 CVEsPage 1 of 3