Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2005-3191

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 85.9%
CVSS Severity
CVSS v2 Score 5.1
References
Products affected by CVE-2005-3191
  • Xpdf » Xpdf » Version: 0.90
    cpe:2.3:a:xpdf:xpdf:0.90
  • Xpdf » Xpdf » Version: 0.91
    cpe:2.3:a:xpdf:xpdf:0.91
  • Xpdf » Xpdf » Version: 0.92
    cpe:2.3:a:xpdf:xpdf:0.92
  • Xpdf » Xpdf » Version: 0.93
    cpe:2.3:a:xpdf:xpdf:0.93
  • Xpdf » Xpdf » Version: 1.0
    cpe:2.3:a:xpdf:xpdf:1.0
  • Xpdf » Xpdf » Version: 1.0a
    cpe:2.3:a:xpdf:xpdf:1.0a
  • Xpdf » Xpdf » Version: 1.1
    cpe:2.3:a:xpdf:xpdf:1.1
  • Xpdf » Xpdf » Version: 2.0
    cpe:2.3:a:xpdf:xpdf:2.0
  • Xpdf » Xpdf » Version: 2.1
    cpe:2.3:a:xpdf:xpdf:2.1
  • Xpdf » Xpdf » Version: 2.2
    cpe:2.3:a:xpdf:xpdf:2.2
  • Xpdf » Xpdf » Version: 2.3
    cpe:2.3:a:xpdf:xpdf:2.3
  • Xpdf » Xpdf » Version: 3.0
    cpe:2.3:a:xpdf:xpdf:3.0
  • Xpdf » Xpdf » Version: 3.0.1
    cpe:2.3:a:xpdf:xpdf:3.0.1
  • Xpdf » Xpdf » Version: 3.0_pl2
    cpe:2.3:a:xpdf:xpdf:3.0_pl2
  • Xpdf » Xpdf » Version: 3.0_pl3
    cpe:2.3:a:xpdf:xpdf:3.0_pl3


Contact Us

Shodan ® - All rights reserved