Search CVE reports


Toggle filters

61 – 70 of 77 results


CVE-2005-3624

Medium priority
Fixed

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-3193

Medium priority
Fixed

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and...

7 affected packages

cupsys, kdegraphics, koffice, pdftohtml, poppler...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
kdegraphics
koffice
pdftohtml
poppler
tetex-bin
xpdf
Show all 7 packages Show less packages

CVE-2005-3192

Medium priority
Fixed

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-3191

Medium priority
Fixed

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a)...

9 affected packages

cupsys, gpdf, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
libextractor
pdftohtml
poppler
tetex-bin
xpdf
Show all 9 packages Show less packages

CVE-2005-2874

Medium priority
Not affected

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

1 affected package

cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
Show less packages

CVE-2005-2097

Low priority

Some fixes available 22 of 23

xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file...

6 affected packages

cups, cupsys, gpdf, kdegraphics, poppler, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
gpdf
kdegraphics
poppler
xpdf
Show less packages

CVE-2005-0206

Medium priority
Fixed

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

3 affected packages

cupsys, tetex-bin, xpdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
tetex-bin
xpdf
Show less packages

CVE-2005-0064

Medium priority
Fixed

Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.

8 affected packages

cupsys, gpdf, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
libextractor
pdftohtml
tetex-bin
xpdf
Show all 8 packages Show less packages

CVE-2004-2154

Medium priority
Not affected

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is...

1 affected package

cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
Show less packages

CVE-2004-1270

Medium priority
Fixed

lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users...

1 affected package

cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
Show less packages