Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-50292 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root … Libinput 1.30.4 / 1.31.3+ Fix from $2,3002026-06-04 CRITICAL 9.1 CVE-2026-46470 An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function d… Gst Plugins Good 1.28.2+ Fix from $2,3002026-05-14 MEDIUM 5.5 CVE-2026-46469 An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function d… Gst Plugins Good 1.28.2+ Fix from $1,6002026-05-14 MEDIUM 6.5 CVE-2025-50420 An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file.… Poppler 25.07.0+ Fix from $1,6002025-08-04 MEDIUM 5.9 CVE-2025-52886 Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits… Poppler 25.06.0+ Fix from $1,6002025-07-02 HIGH 7.1 CVE-2025-32365 Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a … Poppler 25.04.0+ Fix from $1,9502025-04-05 MEDIUM 5.5 CVE-2025-32364 A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs a… Poppler 25.04.0+ Fix from $1,6002025-04-05 MEDIUM 6.5 CVE-2022-37052 A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject. Poppler Patch available Fix from $1,6002023-08-22 MEDIUM 6.5 CVE-2022-38349 An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDic… Poppler Patch available Fix from $1,6002023-08-22 MEDIUM 6.5 CVE-2020-18839 Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service. Poppler No fix yet Fix from $1,6002023-08-22 MEDIUM 6.5 CVE-2020-36023 An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to F… Poppler Patch available Fix from $1,6002023-08-11 MEDIUM 5.5 CVE-2020-36024 An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to F… Poppler Patch available Fix from $1,6002023-08-11 MEDIUM 5.5 CVE-2023-34872 A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file… Poppler 23.06.0+ Fix from $1,6002023-07-31 HIGH 7.4 CVE-2022-4055 When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbir… Xdg Utils after 1.1.3 Fix from $1,9502022-11-19 HIGH 7.8 CVE-2022-31782 ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow. Freetype Demo Programs after 2.12.1 Fix from $1,9502022-06-02 HIGH 7.8 CVE-2022-1215 A format string vulnerability was found in libinput Libinput 1.18.2 / 1.19.4+ Fix from $1,9502022-06-02 MEDIUM 6.5 CVE-2020-27748 A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreet… Xdg Utils No fix yet Fix from $1,6002021-06-01 HIGH 7.8 CVE-2020-35512 A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1… Dbus Mitigation only Fix from $1,9502021-02-15 CRITICAL 9.8 CVE-2021-3185 A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stac… Gst Plugins Bad 1.18.1+ Fix from $2,3002021-01-26 HIGH 7.8 CVE-2020-35702 DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that… Poppler No fix yet Fix from $1,9502020-12-25 MEDIUM 5.5 CVE-2020-16127 An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read … Accountsservice 0.6.55+ Fix from $1,6002020-11-11 HIGH 8.8 CVE-2018-21009 Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. Poppler 0.76.0+ Fix from $1,9502019-09-05 HIGH 8.8 CVE-2019-12293 In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or width… Poppler after 0.76.1 Fix from $1,9502019-05-23 MEDIUM 6.5 CVE-2019-10873 An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc. Poppler No fix yet Fix from $1,6002019-04-05 HIGH 8.8 CVE-2019-10872 An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. Poppler No fix yet Fix from $1,9502019-04-05 MEDIUM 6.5 CVE-2019-10871 An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc. Poppler No fix yet Fix from $1,6002019-04-05 HIGH 8.8 CVE-2019-9543 An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered… Poppler No fix yet Fix from $1,9502019-03-01 HIGH 8.8 CVE-2019-9545 An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by… Poppler No fix yet Fix from $1,9502019-03-01 MEDIUM 6.5 CVE-2018-14036 Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authori… Accountsservice 0.6.50+ Fix from $1,6002018-07-13 HIGH 7.5 CVE-2017-14929 In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::exe… Poppler Mitigation only Fix from $1,9502017-09-30