Vulnerability Details CVE-2009-3605
Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.044
EPSS Ranking 88.3%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2009-3605
-
cpe:2.3:a:poppler:poppler:*
-
cpe:2.3:a:poppler:poppler:0.1
-
cpe:2.3:a:poppler:poppler:0.1.1
-
cpe:2.3:a:poppler:poppler:0.1.2
-
cpe:2.3:a:poppler:poppler:0.10.0
-
cpe:2.3:a:poppler:poppler:0.10.1
-
cpe:2.3:a:poppler:poppler:0.10.2
-
cpe:2.3:a:poppler:poppler:0.10.3
-
cpe:2.3:a:poppler:poppler:0.10.4
-
cpe:2.3:a:poppler:poppler:0.2.0
-
cpe:2.3:a:poppler:poppler:0.3.0
-
cpe:2.3:a:poppler:poppler:0.3.1
-
cpe:2.3:a:poppler:poppler:0.3.2
-
cpe:2.3:a:poppler:poppler:0.3.3
-
cpe:2.3:a:poppler:poppler:0.4.0
-
cpe:2.3:a:poppler:poppler:0.4.1
-
cpe:2.3:a:poppler:poppler:0.4.2
-
cpe:2.3:a:poppler:poppler:0.4.3
-
cpe:2.3:a:poppler:poppler:0.4.4
-
cpe:2.3:a:poppler:poppler:0.5.0
-
cpe:2.3:a:poppler:poppler:0.5.1
-
cpe:2.3:a:poppler:poppler:0.5.2
-
cpe:2.3:a:poppler:poppler:0.5.3
-
cpe:2.3:a:poppler:poppler:0.5.4
-
cpe:2.3:a:poppler:poppler:0.5.9
-
cpe:2.3:a:poppler:poppler:0.5.90
-
cpe:2.3:a:poppler:poppler:0.5.91
-
cpe:2.3:a:poppler:poppler:0.6.0
-
cpe:2.3:a:poppler:poppler:0.6.1
-
cpe:2.3:a:poppler:poppler:0.6.2
-
cpe:2.3:a:poppler:poppler:0.6.3
-
cpe:2.3:a:poppler:poppler:0.6.4
-
cpe:2.3:a:poppler:poppler:0.7.0
-
cpe:2.3:a:poppler:poppler:0.7.1
-
cpe:2.3:a:poppler:poppler:0.7.2
-
cpe:2.3:a:poppler:poppler:0.7.3
-
cpe:2.3:a:poppler:poppler:0.8.0
-
cpe:2.3:a:poppler:poppler:0.8.1
-
cpe:2.3:a:poppler:poppler:0.8.2
-
cpe:2.3:a:poppler:poppler:0.8.3
-
cpe:2.3:a:poppler:poppler:0.8.4
-
cpe:2.3:a:poppler:poppler:0.8.5
-
cpe:2.3:a:poppler:poppler:0.8.6
-
cpe:2.3:a:poppler:poppler:0.8.7
-
cpe:2.3:a:poppler:poppler:0.9.0
-
cpe:2.3:a:poppler:poppler:0.9.1
-
cpe:2.3:a:poppler:poppler:0.9.2
-
cpe:2.3:a:poppler:poppler:0.9.3