Vulnerabilities in poppler
11 resultsVexday analysis
A biblioteca Poppler apresenta 6 vulnerabilidades documentadas, nenhuma delas em exploração ativa conhecida ou com severidade crítica, o que reduz significativamente o risco imediato. A fraqueza dominante é use-after-free (CWE-416), típica em processamento de PDF, com potencial para negação de serviço ou execução de código em contextos específicos. Não há indicadores de risco recente, sendo recomendada monitoração contínua mas sem urgência de ação imediata.
CVE-2017-2820HIGHAn exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A speciEPSS 4.4%CVE-2012-2142—The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escapeEPSS 2.9%CVE-2017-2814HIGHAn exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cauEPSS 2.6%CVE-2017-2818HIGHAn exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cauEPSS 1.8%CVE-2010-4653—An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.EPSS 1.8%CVE-2017-7511—poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.EPSS 1.8%CVE-2010-4654—poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.EPSS 1.2%CVE-2010-0207—In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-basEPSS 0.8%CVE-2025-52886MEDIUMPoppler Use After Free VulnerabilityEPSS 0.4%CVE-2026-12600HIGHUncontrolled memory usage in Innodata Labs’ Poppler JPX decoderEPSS 0.3%CVE-2025-52885MEDIUMGHSL-2025-042: Poppler has Use-After-FreeEPSS 0.2%