Search CVE reports


Toggle filters

131 – 140 of 188 results


CVE-2019-12360

Low priority
Vulnerable

A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an...

7 affected packages

emscripten, ipe, texlive-bin, libextractor, xpdf...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
emscripten Ignored Ignored Not in release Ignored
ipe Not affected Not affected Not affected Not affected
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
libextractor Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2019-9589

Low priority
Ignored

There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an...

6 affected packages

xpdf, ipe, libextractor, poppler, texlive-bin, utopia-documents

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not in release Not affected
ipe Not affected Not affected Not affected
libextractor Not affected Not affected Not affected
poppler Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release
Show less packages

CVE-2019-9588

Low priority
Vulnerable

There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service...

6 affected packages

texlive-bin, libextractor, ipe, xpdf, poppler, utopia-documents

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
libextractor Not affected Not affected Not affected Not affected
ipe Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9587

Negligible priority
Vulnerable

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service...

6 affected packages

texlive-bin, ipe, libextractor, poppler, utopia-documents, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Vulnerable Vulnerable Vulnerable Vulnerable
ipe Not affected Not affected Not affected Not affected
libextractor Not affected Not affected Not affected Not affected
poppler Not affected Not affected Not affected Not affected
utopia-documents Not in release Not in release Not in release Not in release
xpdf Not affected Not affected Not in release Not affected
Show less packages

CVE-2018-17407

Medium priority
Fixed

An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded...

1 affected package

texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Fixed
Show less packages

CVE-2017-17513

Negligible priority
Vulnerable

TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to...

3 affected packages

context, texlive-base, texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
context Needs evaluation Needs evaluation Needs evaluation Needs evaluation
texlive-base Vulnerable Vulnerable Vulnerable Vulnerable
texlive-bin Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2015-5701

Medium priority
Not affected

mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of a fix of CVE-2015-5700.

1 affected package

texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin
Show less packages

CVE-2015-5700

Low priority
Fixed

mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.

1 affected package

texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
texlive-bin Not affected
Show less packages

CVE-2017-9233

Medium priority

Some fixes available 7 of 102

XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.

33 affected packages

apache2, apr-util, cmake, expat, ghostscript...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
expat Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
vnc4 Not in release Not in release Not in release Ignored
texlive-bin Not affected Not affected Not affected Not affected
wxwidgets2.6 Not in release Not in release Not in release Not in release
kompozer Not in release Not in release Not in release Not in release
libparagui1.1 Not in release Not in release Not in release Not in release
poco Not affected Not affected Not affected Not affected
ayttm Not in release Not in release Not in release Not in release
audacity Not affected Not affected Not affected Not affected
matanza Ignored Ignored Ignored Ignored
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
coin3 Not affected Not affected Not affected Needs evaluation
cableswig Not in release Not in release Not in release Not in release
cadaver Not affected Not affected Not affected Not affected
insighttoolkit4 Not in release Not affected Not affected Not affected
sitecopy Not in release Not affected Not affected Not affected
gdcm Not affected Not affected Not affected Not affected
insighttoolkit Not in release Not in release Not in release Not in release
libxmltok Not affected Not affected Not affected Not affected
tla Not affected Not affected Not affected Not affected
wbxml2 Not affected Not affected Not affected Not affected
vtk Not in release Not in release Not in release Not in release
firefox Not affected Not affected Not in release Not affected
simgear Not affected Not affected Not affected Not affected
smart Not in release Not in release Not in release Not affected
tdom Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
wxwidgets2.8 Not in release Not in release Not in release Not in release
xmlrpc-c Not affected Not affected Not affected Not affected
Show all 33 packages Show less packages

CVE-2017-9083

Low priority

Some fixes available 8 of 9

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

3 affected packages

luatex, poppler, texlive-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
luatex Not in release
poppler Fixed
texlive-bin Not affected
Show less packages