Vulnerabilities
Vulnerable Software
Glyphandcog:  >> Xpdfreader  Security Vulnerabilities
xpdfreader 4.03 is vulnerable to Buffer Overflow.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-11-10
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
CVSS Score
7.8
EPSS Score
0.001
Published
2022-08-30
Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
CVSS Score
7.8
EPSS Score
0.001
Published
2022-08-30
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
CVSS Score
5.5
EPSS Score
0.003
Published
2019-10-01
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-09-08
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-09-06
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-09-03
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-07-27
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-07-27
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-07-27


Contact Us

Shodan ® - All rights reserved