📦

poppler

Vendor: freedesktop

Actively Exploited 1 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 9 Remote Access
Total CVEs 489 Total Indexed
Avg. EPSS 1.98% Exploit Prob.
Latest CVE CVE-2025-50420 Aug 04

Security Vulnerability Index

Page 3 / 49
7.8 CVSS

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects

EPSS: 0.44%
7.5 CVSS

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

EPSS: 1.12%
7.8 CVSS

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

EPSS: 0.40%
7.8 CVSS

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

EPSS: 0.47%
6.5 CVSS

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

EPSS: 0.78%
8.8 CVSS

Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

EPSS: 0.48%
7.5 CVSS

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

EPSS: 1.93%
6.5 CVSS

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

EPSS: 1.45%
8.8 CVSS

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

EPSS: 0.95%
6.5 CVSS

FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.

EPSS: 0.51%