📦

xpdf

Vendor: foolabs

Actively Exploited 1 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 21 Remote Access
Total CVEs 51 Total Indexed
Avg. EPSS 3.02% Exploit Prob.
Latest CVE CVE-2024-7868 Aug 15

Security Vulnerability Index

Page 6 / 6
7.8 CVSS

There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

EPSS: 1.05%
7.8 CVSS

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

EPSS: 2.94%
5.5 CVSS

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

EPSS: 0.85%
5.5 CVSS

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

EPSS: 1.06%
5.5 CVSS

Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.

EPSS: 0.86%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.

EPSS: 0.87%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

EPSS: 0.87%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.

EPSS: 0.87%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.

EPSS: 0.89%
5.5 CVSS

An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.

EPSS: 0.88%