📦

xpdf

Vendor: xpdf

Actively Exploited 1 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 41 Remote Access
Total CVEs 27 Total Indexed
Avg. EPSS 3.37% Exploit Prob.
Latest CVE CVE-2024-7868 Aug 15

Security Vulnerability Index

Page 3 / 3
5.5 CVSS

A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

EPSS: 0.09%
5.5 CVSS

XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.

EPSS: 0.08%
5.5 CVSS

An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.

EPSS: 0.07%
5.5 CVSS

An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.

EPSS: 0.10%
5.5 CVSS

An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.

EPSS: 0.33%
7.8 CVSS

There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

EPSS: 0.17%
7.8 CVSS

XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

EPSS: 0.16%
5.5 CVSS

XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.

EPSS: 0.21%
5.5 CVSS

XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.

EPSS: 0.10%
7.8 CVSS

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

EPSS: 0.12%