Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libinput CRITICAL 9.8
CVE-2026-50292

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root …

Fix: 1.30.4 / 1.31.3+
Fix from $2,300 2026-06-04
Gst Plugins Good CRITICAL 9.1
CVE-2026-46470

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function d…

Fix: 1.28.2+
Fix from $2,300 2026-05-14
Gst Plugins Good MEDIUM 5.5
CVE-2026-46469

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function d…

Fix: 1.28.2+
Fix from $1,600 2026-05-14
Poppler MEDIUM 6.5
CVE-2025-50420

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file.…

Fix: 25.07.0+
Fix from $1,600 2025-08-04
Poppler MEDIUM 5.9
CVE-2025-52886

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits…

Fix: 25.06.0+
Fix from $1,600 2025-07-02
Poppler HIGH 7.1
CVE-2025-32365

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a …

Fix: 25.04.0+
Fix from $1,950 2025-04-05
Poppler MEDIUM 5.5
CVE-2025-32364

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs a…

Fix: 25.04.0+
Fix from $1,600 2025-04-05
Poppler MEDIUM 6.5
CVE-2022-37052

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.

Patch available
Fix from $1,600 2023-08-22
Poppler MEDIUM 6.5
CVE-2022-38349

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDic…

Patch available
Fix from $1,600 2023-08-22
Poppler MEDIUM 6.5
CVE-2020-18839

Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

No fix yet
Fix from $1,600 2023-08-22
Poppler MEDIUM 6.5
CVE-2020-36023

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to F…

Patch available
Fix from $1,600 2023-08-11
Poppler MEDIUM 5.5
CVE-2020-36024

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to F…

Patch available
Fix from $1,600 2023-08-11
Poppler MEDIUM 5.5
CVE-2023-34872

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file…

Fix: 23.06.0+
Fix from $1,600 2023-07-31
Xdg Utils HIGH 7.4
CVE-2022-4055

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbir…

Fix: after 1.1.3
Fix from $1,950 2022-11-19
Freetype Demo Programs HIGH 7.8
CVE-2022-31782

ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

Fix: after 2.12.1
Fix from $1,950 2022-06-02
Libinput HIGH 7.8
CVE-2022-1215

A format string vulnerability was found in libinput

Fix: 1.18.2 / 1.19.4+
Fix from $1,950 2022-06-02
Xdg Utils MEDIUM 6.5
CVE-2020-27748

A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreet…

No fix yet
Fix from $1,600 2021-06-01
Dbus HIGH 7.8
CVE-2020-35512

A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1…

Mitigation only
Fix from $1,950 2021-02-15
Gst Plugins Bad CRITICAL 9.8
CVE-2021-3185

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stac…

Fix: 1.18.1+
Fix from $2,300 2021-01-26
Poppler HIGH 7.8
CVE-2020-35702

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that…

No fix yet
Fix from $1,950 2020-12-25
Accountsservice MEDIUM 5.5
CVE-2020-16127

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read …

Fix: 0.6.55+
Fix from $1,600 2020-11-11
Poppler HIGH 8.8
CVE-2018-21009

Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

Fix: 0.76.0+
Fix from $1,950 2019-09-05
Poppler HIGH 8.8
CVE-2019-12293

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or width…

Fix: after 0.76.1
Fix from $1,950 2019-05-23
Poppler MEDIUM 6.5
CVE-2019-10873

An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

No fix yet
Fix from $1,600 2019-04-05
Poppler HIGH 8.8
CVE-2019-10872

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.

No fix yet
Fix from $1,950 2019-04-05
Poppler MEDIUM 6.5
CVE-2019-10871

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

No fix yet
Fix from $1,600 2019-04-05
Poppler HIGH 8.8
CVE-2019-9543

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered…

No fix yet
Fix from $1,950 2019-03-01
Poppler HIGH 8.8
CVE-2019-9545

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by…

No fix yet
Fix from $1,950 2019-03-01
Accountsservice MEDIUM 6.5
CVE-2018-14036

Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authori…

Fix: 0.6.50+
Fix from $1,600 2018-07-13
Poppler HIGH 7.5
CVE-2017-14929

In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::exe…

Mitigation only
Fix from $1,950 2017-09-30