Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 10 of 45 results


CVE-2010-3704

Medium priority

Some fixes available 9 of 75

The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Not affected Not affected Not affected Not affected Not affected
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2010-3703

Medium priority

Some fixes available 4 of 72

The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Not affected Not affected Not affected Not affected Not affected
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2010-3702

Medium priority

Some fixes available 9 of 75

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Not affected Not affected Not affected Not affected Not affected
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2009-3609

Medium priority

Some fixes available 38 of 106

Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Fixed Fixed Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2009-3608

Medium priority

Some fixes available 38 of 106

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Fixed Fixed Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2009-3606

Medium priority

Some fixes available 7 of 75

Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Not affected Not affected Not affected Not affected Not affected
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2009-3604

Medium priority

Some fixes available 37 of 103

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Fixed Fixed Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2009-3603

Medium priority

Some fixes available 37 of 103

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer...

11 affected packages

gpdf, ipe, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gpdf Not in release Not in release Not in release Not in release Not in release
ipe Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kdegraphics Not in release Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release Not in release
poppler Fixed Fixed Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected Not affected
xpdf Not affected Not affected Not in release Not affected Not affected
Show all 11 packages Show less packages

CVE-2009-1188

Medium priority

Some fixes available 34 of 74

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to...

14 affected packages

cups, cupsys, evince, gpdf, ipe...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cups Not affected Not affected Not affected Not affected
cupsys Not in release Not in release Not in release Not in release
evince Not affected Not affected Not affected Not affected
gpdf Not in release Not in release Not in release Not in release
ipe Not affected Not affected Not affected Not affected
kdegraphics Not in release Not in release Not in release Not in release
koffice Not in release Not in release Not in release Not in release
libextractor Not affected Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release Not in release
poppler Fixed Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected Not affected
xpdf Not affected Not in release Not affected Not affected
Show all 14 packages Show less packages

CVE-2009-1187

Medium priority

Some fixes available 5 of 19

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

14 affected packages

cups, cupsys, evince, gpdf, ipe...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cups
cupsys
evince
gpdf
ipe
kdegraphics
koffice
libextractor
pdfkit.framework
pdftohtml
poppler
tetex-bin
texlive-bin
xpdf
Show all 14 packages Show less packages