Search CVE reports


Toggle filters

1 – 10 of 203 results


CVE-2025-52886

Medium priority

Some fixes available 6 of 7

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free....

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-50420

Medium priority
Needs evaluation

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-43903

Medium priority
Fixed

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-32365

Medium priority
Fixed

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-32364

Medium priority
Fixed

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-6239

Low priority

Some fixes available 2 of 6

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Ignored Ignored
Show less packages

CVE-2024-56378

Medium priority
Fixed

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-3900

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.

3 affected packages

poppler, xpdf, ipe

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-34872

Medium priority
Fixed

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

1 affected package

poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Not affected Not affected
Show less packages

CVE-2022-38784

Medium priority

Some fixes available 4 of 13

Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the...

2 affected packages

emscripten, poppler

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
emscripten Needs evaluation Needs evaluation Not in release Needs evaluation
poppler Not affected Fixed Fixed Fixed
Show less packages