ZeroHour

Vulnerabilities

106 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50292
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execut

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

NVD description · AI analysis pending
9.8<1%
  • freedesktop libinput
CVE-2026-46470
+1 in the same advisory: …46469
An issue was discovered in GStreamer gst-plugins-good before 1.28.2.

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before performing division operations, leading to denial of service due to integer division by zero.

NVD description · AI analysis pending
9.1
group max
<1%
  • freedesktop gst-plugins-good
CVE-2026-35093
+1 in the same advisory: …35094
A flaw was found in libinput.

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

NVD description · AI analysis pending
8.8
group max
<1%
  • freedesktop libinput
  • freedesktop fedora
CVE-2026-4897
A flaw was found in polkit.

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.

NVD description · AI analysis pending
5.5<1%
  • freedesktop polkit
  • freedesktop openshift container platform
  • freedesktop enterprise linux
CVE-2026-1940
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function.

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.

NVD description · AI analysis pending
7.5<1%
  • freedesktop gst-plugins-good
  • freedesktop gstreamer
  • freedesktop debian linux
  • +1 more
CVE-2026-26103
+1 in the same advisory: …26104
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.

NVD description · AI analysis pending
7.1
group max
<1%
  • redhat enterprise linux
  • redhat udisks
CVE-2025-50420
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file.

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

NVD description · AI analysis pending
6.5<1% PoC
  • freedesktop poppler
CVE-2025-52886
Poppler is a PDF rendering library.

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • freedesktop poppler
CVE-2025-43903
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

NVD description · AI analysis pending
3.3<1%
  • freedesktop poppler
CVE-2025-32365
+1 in the same advisory: …32364
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced i

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

NVD description · AI analysis pending
7.1
group max
<1% PoC
  • freedesktop poppler
CVE-2024-56378
libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

NVD description · AI analysis pending
4.3<1% PoC
  • freedesktop poppler
CVE-2024-6239
A flaw was found in the Poppler's Pdfinfo utility.

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

NVD description · AI analysis pending
7.5<1%
  • freedesktop poppler
  • freedesktop enterprise linux
CVE-2020-23804
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.

Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.

NVD description · AI analysis pending
7.5
group max
1% PoC
  • freedesktop poppler
  • freedesktop debian linux
CVE-2020-36023
+1 in the same advisory: …36024
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

NVD description · AI analysis pending
6.5
group max
1% PoC
  • freedesktop poppler
CVE-2023-34872
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in Outline

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

NVD description · AI analysis pending
5.5<1% PoC
  • freedesktop poppler
CVE-2023-34969
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon.

D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.

NVD description · AI analysis pending
6.51% PoC
  • freedesktop dbus
  • freedesktop fedora
  • freedesktop debian linux
CVE-2022-4055
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that shou

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

NVD description · AI analysis pending
7.4<1% PoC
  • freedesktop xdg-utils
CVE-2022-42012
+2 in the same advisory: …42011 …42010
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2.

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

NVD description · AI analysis pending
6.51% PoC
  • freedesktop dbus
  • freedesktop fedora
CVE-2022-38784
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc).

Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.

NVD description · AI analysis pending
7.8<1% PoC
  • freedesktop poppler
  • freedesktop debian linux
  • freedesktop fedora
CVE-2022-38171
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc).

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

NVD description · AI analysis pending
7.8<1%
  • xpdfreader xpdf
  • xpdfreader poppler
CVE-2022-31782
ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

NVD description · AI analysis pending
7.8<1%
  • freedesktop freetype demo programs
CVE-2022-1215
A format string vulnerability was found in libinput

A format string vulnerability was found in libinput

NVD description · AI analysis pending
7.8<1%
  • freedesktop libinput
CVE-2022-27337
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

NVD description · AI analysis pending
6.52% PoC ×2
  • freedesktop poppler
  • freedesktop fedora
  • freedesktop debian linux
CVE-2021-30860
Integer Overflow in Apple PDF Processing Enables Arbitrary Code Execution (CVE-2021-30860)

CVE-2021-30860 is an integer overflow (CWE-190) in PDF processing across Apple's platforms that was addressed with improved input validation. It is triggered when a device processes a maliciously crafted PDF — notably when a PDF is rendered after being received via messaging — and successful exploitation allows arbitrary code execution in the context of the PDF renderer. Affected products include iOS/iPadOS, macOS (Big Sur and Catalina), and watchOS, as well as the Xpdf and Poppler PDF libraries, which share lineage with the vulnerable code. Apple confirmed the issue was being actively exploited in the wild, and public reporting ties it to NSO Group's 'ForcedEntry' exploit chain used to deliver Pegasus spyware; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Given the very high EPSS score (76%, 99th percentile) and confirmed active exploitation, defenders should treat this as a high-priority patch.

Do: Update iPhones/iPads to iOS/iPadOS 14.8, Macs to macOS Big Sur 11.6 (or apply Security Update 2021-005 Catalina), and Apple Watch to watchOS 7.6.2 immediately, and patch Poppler/Xpdf through distribution or vendor updates. Because the flaw was exploited via crafted PDFs delivered through messaging (ForcedEntry/Pegasus), organizations and individuals at risk of targeted spyware should also review devices for signs of compromise. CISA KEV requires applying updates per vendor instructions; prioritize internet-connected and high-value user endpoints.

7.876% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 14.8 (fixed in iOS 14.8)
  • Apple iPadOS versions prior to iPadOS 14.8 (fixed in iPadOS 14.8)
  • Apple macOS Catalina fixed by Security Update 2021-005 Catalina
  • +4 more
mass>1 billion active Apple devices (iPhones, iPads, Macs, Apple Watches), plus Poppler present by default on most Linux desktops and servers
CVE-2020-27748
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer.

A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.

NVD description · AI analysis pending
6.51% PoC
  • freedesktop xdg-utils
CVE-2020-35512
A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when

A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharing the same UID. When a set of policy rules references these usernames, D-Bus may free some memory in the heap, which is still used by data structures necessary for the other usernames sharing the UID, possibly leading to a crash or other undefined behaviors

NVD description · AI analysis pending
7.8<1%
  • freedesktop dbus
CVE-2021-3185
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be sma

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.

NVD description · AI analysis pending
9.82%
  • freedesktop gst-plugins-bad
CVE-2020-35702
DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document.

DCTStream::getChars in DCTStream.cc in Poppler 20.12.1 has a heap-based buffer overflow via a crafted PDF document. NOTE: later reports indicate that this only affects builds from Poppler git clones in late December 2020, not the 20.12.1 release. In this situation, it should NOT be considered a Poppler vulnerability. However, several third-party Open Source projects directly rely on Poppler git clones made at arbitrary times, and therefore the CVE remains useful to users of those projects

NVD description · AI analysis pending
7.8<1% PoC
  • freedesktop poppler
CVE-2020-27778
A flaw was found in Poppler in the way certain PDF files were converted into HTML.

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

NVD description · AI analysis pending
7.52% PoC
  • freedesktop poppler
  • freedesktop enterprise linux
  • freedesktop debian linux
CVE-2020-16127
+1 in the same advisory: …16126
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • freedesktop accountsservice
CVE-2020-12049
An issue was discovered in dbus >= 1.3.0 before 1.12.18.

An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • freedesktop dbus
  • freedesktop ubuntu linux
CVE-2019-20367
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

NVD description · AI analysis pending
9.13% PoC
  • freedesktop libbsd
  • freedesktop debian linux
  • freedesktop ubuntu linux
  • +1 more
CVE-2018-21009
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.

NVD description · AI analysis pending
8.82%
  • freedesktop poppler
CVE-2019-14494
An issue was discovered in Poppler through 0.78.0.

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

NVD description · AI analysis pending
7.53% PoC
  • freedesktop poppler
  • freedesktop ubuntu linux
  • freedesktop fedora
  • +1 more
CVE-2019-9959
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

NVD description · AI analysis pending
6.52%
  • freedesktop poppler
  • freedesktop debian linux
  • freedesktop fedora
  • +1 more
CVE-2019-12749
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, use

dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.

NVD description · AI analysis pending
7.1<1%
  • freedesktop dbus
  • freedesktop ubuntu linux
CVE-2019-12293
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

NVD description · AI analysis pending
8.82% PoC
  • freedesktop poppler