📦

poppler

Vendor: poppler

Actively Exploited 1 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 25 Remote Access
Total CVEs 30 Total Indexed
Avg. EPSS 3.81% Exploit Prob.
Latest CVE CVE-2025-50420 Aug 04

Security Vulnerability Index

Page 1 / 3
6.5 CVSS

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

EPSS: 0.17%
5.5 CVSS

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

EPSS: 0.28%
4.3 CVSS

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

EPSS: 0.03%
4.0 CVSS

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

EPSS: 0.07%
4.0 CVSS

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

EPSS: 0.07%
4.3 CVSS

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

EPSS: 0.30%
7.5 CVSS
CVE-2024-6239
Exploit Found

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

EPSS: 0.13%
6.5 CVSS

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

EPSS: 0.02%
6.5 CVSS

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.

EPSS: 0.03%
6.5 CVSS

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.

EPSS: 0.04%