VendorsXpdfReaderxpdfall versions
Vulnerabilities

XpdfReader Xpdf

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

82CVEs
CVE-2019-10024
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.
Published 2019-03-24 · Modified
5.5EPSS 0.009
CVE-2019-10025
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.
Published 2019-03-24 · Modified
5.5EPSS 0.009
CVE-2019-10026
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.
Published 2019-03-24 · Modified
5.5EPSS 0.009
CVE-2010-0207
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
Published 2019-10-30 · Modified
5.5EPSS 0.008
CVE-2018-7174
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.
Published 2018-02-15 · Modified
5.5EPSS 0.008
CVE-2022-30775
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.
Published 2022-05-16 · Modified
5.5EPSS 0.008
CVE-2018-7175
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.
Published 2018-02-15 · Modified
5.5EPSS 0.008
CVE-2018-8103
The JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2018-7452
A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-02-24 · Modified
5.5EPSS 0.008
CVE-2018-7454
A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-02-24 · Modified
5.5EPSS 0.008
CVE-2018-7455
An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-02-24 · Modified
5.5EPSS 0.008
CVE-2018-8101
The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2018-8102
The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2018-8104
The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2018-7173
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.
Published 2018-02-15 · Modified
5.5EPSS 0.008
CVE-2018-8105
The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2018-8106
The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2018-8107
The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.
Published 2018-03-14 · Modified
5.5EPSS 0.008
CVE-2021-27548
There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
Published 2022-05-18 · Modified
5.5EPSS 0.007
CVE-2022-38334
XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
Published 2022-09-15 · Modified
5.5EPSS 0.004
CVE-2022-41842
An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
Published 2022-09-30 · Modified
5.5EPSS 0.004
CVE-2022-41844
An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.
Published 2022-09-30 · Modified
5.5EPSS 0.004
CVE-2022-41843
An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.
Published 2022-09-30 · Modified
5.5EPSS 0.003
CVE-2022-36561
XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
Published 2022-08-30 · Modified
5.5EPSS 0.003
CVE-2022-43071
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Published 2022-11-15 · Modified
5.5EPSS 0.003
CVE-2023-26930
Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”
Published 2023-04-26 · Modified
5.5EPSS 0.003
CVE-2022-45587
Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.
Published 2023-02-15 · Modified
5.5EPSS 0.003
CVE-2022-45586
Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.
Published 2023-02-15 · Modified
5.5EPSS 0.003
CVE-2023-2664
Stack overflow in Xpdf 4.04 due to object loop in PDF embedded file tree
Published 2023-05-11 · Modified
5.5EPSS 0.003
CVE-2024-3247
Stack overflow in Xpdf 4.05 due to object loop in PDF object stream
Published 2024-04-02 · Analyzed
5.5EPSS 0.003
CVE-2024-3248
Stack overflow in Xpdf 4.05 due to object loop in attachments
Published 2024-04-02 · Analyzed
5.5EPSS 0.003
CVE-2023-2662
Divide-by-zero in Xpdf 4.04 due to bad color space object
Published 2023-05-11 · Modified
5.5EPSS 0.003
CVE-2022-43295
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
Published 2022-11-14 · Modified
5.5EPSS 0.003
CVE-2022-48545
An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2024-4568
Stack overflow in Xpdf 4.05 due to object loop in PDF resources
Published 2024-05-06 · Analyzed
5.5EPSS 0.002
CVE-2024-7866
Stack overflow in Xpdf 4.05 due to object loop in PDF pattern
Published 2024-08-15 · Analyzed
5.5EPSS 0.002
CVE-2024-4141
Out-of-bounds array write in Xpdf 4.05 due to incorrect bounds check
Published 2024-04-24 · Analyzed
5.5EPSS 0.002
CVE-2024-2971
Out-of-bounds array access due to negative object numbers in indirect references in Xpdf 4.05
Published 2024-03-26 · Analyzed
5.5EPSS 0.002
CVE-2024-3900
Out-of-bounds stack array write in Xpdf 4.05 due to missing zero check
Published 2024-04-17 · Analyzed
5.5EPSS 0.002
CVE-2024-4976
Out-of-bounds array write in Xpdf 4.05 due to missing object type check
Published 2024-05-15 · Analyzed
5.5EPSS 0.002
← Prev2 / 3Next →