📦

xpdf

Vendor: xpdfreader

Actively Exploited 1 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 17 Remote Access
Total CVEs 83 Total Indexed
Avg. EPSS 1.48% Exploit Prob.
Latest CVE CVE-2024-7868 Aug 15

Security Vulnerability Index

Page 5 / 9
7.8 CVSS

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

EPSS: 0.40%
5.5 CVSS

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

EPSS: 0.44%
5.5 CVSS

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

EPSS: 0.44%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.

EPSS: 0.16%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

EPSS: 0.16%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.

EPSS: 0.16%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.

EPSS: 0.16%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.

EPSS: 0.18%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps.

EPSS: 0.16%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.

EPSS: 0.16%