Search CVE reports


Toggle filters

1 – 10 of 214 results


CVE-2026-102621

Medium priority
Needs evaluation

A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-102620

Medium priority
Needs evaluation

A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93653

Medium priority
Needs evaluation

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93314

Medium priority
Needs evaluation

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow....

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93313

Medium priority
Needs evaluation

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93312

Medium priority
Needs evaluation

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-93311

Medium priority
Needs evaluation

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-10118

Medium priority

Some fixes available 4 of 7

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2018-25306

Medium priority
Needs evaluation

PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmentation fault in...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-52885

Medium priority
Fixed

Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue...

1 affected package

poppler

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
poppler — Fixed Fixed Fixed Not affected
Show less packages