Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Poppler MEDIUM 5.5
CVE-2017-14927

In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Poppler HIGH 7.8
CVE-2017-14617

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malici…

Mitigation only
Fix from $1,950 2017-09-20
Poppler HIGH 7.8
CVE-2017-14518

In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.

No fix yet
Fix from $1,950 2017-09-17
Poppler HIGH 7.8
CVE-2017-14520

In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling mal…

No fix yet
Fix from $1,950 2017-09-17
Poppler HIGH 7.5
CVE-2017-14519

In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::ex…

No fix yet
Fix from $1,950 2017-09-17
Poppler MEDIUM 5.5
CVE-2017-14517

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

No fix yet
Fix from $1,600 2017-09-17
Poppler HIGH 8.8
CVE-2017-2814

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an ima…

Mitigation only
Fix from $1,950 2017-07-12
Poppler HIGH 8.8
CVE-2017-2818

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an ove…

Mitigation only
Fix from $1,950 2017-07-12
Poppler HIGH 8.8
CVE-2017-2820

An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially craf…

No fix yet
Fix from $1,950 2017-07-12
Poppler MEDIUM 5.5
CVE-2017-7515

poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

Fix: after 0.55.0
Fix from $1,600 2017-06-06
Poppler MEDIUM 5.5
CVE-2017-7511

poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.

Patch available
Fix from $1,600 2017-05-30
Poppler MEDIUM 6.5
CVE-2017-9083

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For exampl…

No fix yet
Fix from $1,600 2017-05-19
Virglrenderer MEDIUM 5.5
CVE-2017-6355

Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial …

Fix: after 0.5.0
Fix from $1,600 2017-03-10
Poppler MEDIUM 5.0
CVE-2013-7296

The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allo…

Fix: after 0.24.3
Fix from $1,600 2014-01-26
Poppler MEDIUM 6.8
CVE-2013-1788

poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that tr…

Fix: after 0.22.0
Fix from $1,600 2013-04-09
Poppler MEDIUM 6.8
CVE-2013-1790

poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninit…

Fix: after 0.22.0
Fix from $1,600 2013-04-09
Dbus Glib HIGH 7.2
CVE-2013-0292

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, …

Fix: after 0.100
Fix from $1,950 2013-03-05
Spice Gtk MEDIUM 6.9
CVE-2012-4425

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute …

Patch available
Fix from $1,600 2012-09-18
Libdbus MEDIUM 6.9
CVE-2012-3524

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileg…

Fix: after 1.5.12
Fix from $1,600 2012-09-18
Telepathy Gabble MEDIUM 6.4
CVE-2011-1000

jingle-factory.c in Telepathy Gabble 0.11 before 0.11.7, 0.10 before 0.10.5, and 0.8 before 0.8.15 allows remote attackers to sniff audio and video c…

Patch available
Fix from $1,600 2011-02-19
Xdg Utils MEDIUM 6.8
CVE-2009-0068

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type th…

Mitigation only
Fix from $1,600 2009-01-07
Scratchbox2 MEDIUM 6.9
CVE-2008-4984

scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, a…

Mitigation only
Fix from $1,600 2008-11-06