Search CVE reports


Toggle filters

1 – 10 of 206 results


CVE-2018-25306

Medium priority
Needs evaluation

PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmentation fault in...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-52885

Medium priority
Fixed

Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-43718

Medium priority

Some fixes available 5 of 8

Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-50420

Medium priority
Fixed

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-52886

Medium priority

Some fixes available 6 of 7

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free....

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-43903

Medium priority
Fixed

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-32365

Medium priority
Fixed

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-32364

Medium priority
Fixed

A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-56378

Medium priority
Fixed

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-6239

Low priority

Some fixes available 2 of 6

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a denial of service.

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Ignored Ignored
Show less packages