Vulnerabilities
77 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-7868 | In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address. NVD description · AI analysis pending | 2.1 | <1% |
| — | ||
| CVE-2024-4976 | Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference. Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference. NVD description · AI analysis pending | 2.1 | <1% |
| — | ||
| CVE-2024-4568 | In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2024-4141 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2024-3900 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText. Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2024-3248 +1 in the same advisory: …3247 | In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow. In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2024-2971 | Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file. Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2022-48545 | An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02. An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-3436 | Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream. Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream. NVD description · AI analysis pending | 3.3 | <1% |
| — | ||
| CVE-2023-3044 | An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate. NVD description · AI analysis pending | 3.3 | <1% | PoC |
| — | |
| CVE-2023-2663 | In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2023-26930 | Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.” NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-45587 +1 in the same advisory: …45586 | Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service. Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2021-36493 | Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2022-43071 | A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-43295 | XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795. XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2022-41842 | An issue was discovered in Xpdf 4.04. An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-38222 | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-38928 | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-38334 | XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc. XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2022-36561 | XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538. XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-38171 | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics). NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2022-33108 | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. NVD description · AI analysis pending | 7.8 | 1% | PoC ×3 |
| — | |
| CVE-2021-27548 | There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03. There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-30775 | xpdf 4.04 allocates excessive memory when presented with crafted input. xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-30524 | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinate There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. NVD description · AI analysis pending | 7.8 | 2% | PoC |
| — | |
| CVE-2022-27135 | xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary. NVD description · AI analysis pending | 5.5 | 1% | PoC ×2 |
| — | |
| CVE-2021-30860 | Integer Overflow in Apple PDF Processing Enables Arbitrary Code Execution (CVE-2021-30860) CVE-2021-30860 is an integer overflow (CWE-190) in PDF processing across Apple's platforms that was addressed with improved input validation. It is triggered when a device processes a maliciously crafted PDF — notably when a PDF is rendered after being received via messaging — and successful exploitation allows arbitrary code execution in the context of the PDF renderer. Affected products include iOS/iPadOS, macOS (Big Sur and Catalina), and watchOS, as well as the Xpdf and Poppler PDF libraries, which share lineage with the vulnerable code. Apple confirmed the issue was being actively exploited in the wild, and public reporting ties it to NSO Group's 'ForcedEntry' exploit chain used to deliver Pegasus spyware; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Given the very high EPSS score (76%, 99th percentile) and confirmed active exploitation, defenders should treat this as a high-priority patch. Do: Update iPhones/iPads to iOS/iPadOS 14.8, Macs to macOS Big Sur 11.6 (or apply Security Update 2021-005 Catalina), and Apple Watch to watchOS 7.6.2 immediately, and patch Poppler/Xpdf through distribution or vendor updates. Because the flaw was exploited via crafted PDFs delivered through messaging (ForcedEntry/Pegasus), organizations and individuals at risk of targeted spyware should also review devices for signs of compromise. CISA KEV requires applying updates per vendor instructions; prioritize internet-connected and high-value user endpoints. | 7.8 | 76% | KEV |
| mass>1 billion active Apple devices (iPhones, iPads, Macs, Apple Watches), plus Poppler present by default on most Linux desktops and servers | |
| CVE-2020-35376 | Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function. Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2020-25725 | In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font. NVD description · AI analysis pending | 5.5 | 1% | PoC ×2 |
| — | |
| CVE-2020-24999 +1 in the same advisory: …24996 | There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2019-10018 | An issue was discovered in Xpdf 4.01.01. An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2019-9878 | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — |