Search CVE reports


Toggle filters

1 – 10 of 167 results


CVE-2025-11896

Medium priority
Needs evaluation

In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the “UseCMap” entry, leads to infinite recursion and a stack overflow.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-3154

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

2 affected packages

ipe, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2025-2574

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-7868

Medium priority
Needs evaluation

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-7867

Medium priority
Needs evaluation

In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-7866

Medium priority
Needs evaluation

In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-4976

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.

2 affected packages

ipe, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2024-4568

Medium priority
Needs evaluation

In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-4141

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

2 affected packages

xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Needs evaluation Needs evaluation Not in release Needs evaluation
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-3900

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.

3 affected packages

poppler, xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages