This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:poppler:poppler |
| Detail | |||
|---|---|---|---|
| Vendor | Poppler | First view | 2005-12-31 |
| Product | Poppler | Last view | 2010-11-05 |
| Version | Type | Application | |
| Edition | |||
| Language | |||
| Update | |||
Activity : Yearly
COMMON PLATFORM ENUMERATION : Repartition per Version
| CPE Name | Affected CVE |
|---|---|
| cpe:/a:poppler:poppler:0.9.3 | 20 |
| cpe:/a:poppler:poppler:0.9.2 | 20 |
| cpe:/a:poppler:poppler:0.9.1 | 20 |
| cpe:/a:poppler:poppler:0.9.0 | 20 |
| cpe:/a:poppler:poppler:0.8.7 | 20 |
Related : CVE
This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 6.8 | 2010-11-05 | CVE-2010-3704 | Network | Medium | None Requ... | |
| 4.3 | 2010-11-05 | CVE-2010-3703 | Network | Medium | None Requ... | |
| 6.8 | 2010-11-05 | CVE-2010-3702 | Network | Medium | None Requ... | |
| 6.8 | 2009-11-13 | CVE-2009-3938 | Network | Medium | None Requ... | |
| 6.8 | 2009-11-02 | CVE-2009-3605 | Network | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2009-10-21 | CVE-2009-3609 | Network | Medium | None Requ... | |
| 9.3 | 2009-10-21 | CVE-2009-3608 | Network | Medium | None Requ... | |
| 9.3 | 2009-10-21 | CVE-2009-3607 | Network | Medium | None Requ... | |
| 9.3 | 2009-10-21 | CVE-2009-3606 | Network | Medium | None Requ... | |
| 9.3 | 2009-10-21 | CVE-2009-3604 | Network | Medium | None Requ... | |
| 9.3 | 2009-10-21 | CVE-2009-3603 | Network | Medium | None Requ... | |
| 5 | 2009-04-23 | CVE-2009-1188 | Network | Low | None Requ... | |
| 5 | 2009-04-23 | CVE-2009-1187 | Network | Low | None Requ... | |
| 4.3 | 2009-04-23 | CVE-2009-1183 | Network | Medium | None Requ... | |
| 7.5 | 2009-04-23 | CVE-2009-1182 | Network | Low | None Requ... | |
| 4.3 | 2009-04-23 | CVE-2009-1181 | Network | Medium | None Requ... | |
| 6.8 | 2009-04-23 | CVE-2009-1180 | Network | Medium | None Requ... | |
| 6.8 | 2009-04-23 | CVE-2009-1179 | Network | Medium | None Requ... | |
| 6.8 | 2009-04-23 | CVE-2009-0800 | Network | Medium | None Requ... | |
| 4.3 | 2009-04-23 | CVE-2009-0799 | Network | Medium | None Requ... | |
| 4.3 | 2009-04-23 | CVE-2009-0166 | Network | Medium | None Requ... | |
| 5 | 2009-03-03 | CVE-2009-0756 | Network | Low | None Requ... | |
| 5 | 2009-03-03 | CVE-2009-0755 | Network | Low | None Requ... | |
| 7.5 | 2008-07-07 | CVE-2008-2950 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 40% (11) | CWE-189 | Numeric Errors |
| 25% (7) | CWE-399 | Resource Management Errors |
| 18% (5) | CWE-20 | Improper Input Validation |
| 11% (3) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
| 3% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
Oval Markup Language : Definitions
| OvalID | Name |
|---|---|
| oval:org.mitre.oval:def:9437 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf... |
| oval:org.mitre.oval:def:9575 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS... |
| oval:org.mitre.oval:def:9992 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS... |
| oval:org.mitre.oval:def:11149 | Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.0... |
| oval:org.mitre.oval:def:11226 | The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly bef... |
| id | Name |
|---|---|
| oval:org.mitre.oval:def:9778 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and ot... |
| oval:org.mitre.oval:def:10204 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Popple... |
| oval:org.mitre.oval:def:11323 | Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and ea... |
| oval:org.mitre.oval:def:11892 | Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9... |
| oval:org.mitre.oval:def:9926 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Popple... |
| oval:org.mitre.oval:def:9683 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Popple... |
| oval:org.mitre.oval:def:10735 | Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlie... |
| oval:org.mitre.oval:def:10769 | The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Po... |
| oval:org.mitre.oval:def:10292 | Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allow... |
| oval:org.mitre.oval:def:9957 | Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBit... |
| oval:org.mitre.oval:def:9671 | Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x befor... |
| oval:org.mitre.oval:def:10969 | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl... |
| oval:org.mitre.oval:def:7731 | Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Librarie... |
| oval:org.mitre.oval:def:7836 | Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Librarie... |
| oval:org.mitre.oval:def:11289 | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.0... |
| oval:org.mitre.oval:def:9536 | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpd... |
| oval:org.mitre.oval:def:8134 | Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Librarie... |
| oval:org.mitre.oval:def:11043 | Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpd... |
Open Source Vulnerability Database (OSVDB)
This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
| id | Description |
|---|---|
| 69064 | Poppler Gfx::getPos PDF Handling Uninitialized Pointer Dereference DoS |
| 69063 | Poppler poppler/Function.cc PostScriptFunction::PostScriptFunction Uninitiali... |
| 69062 | Poppler fofi/FoFiType1.cc FoFiType1::parse Function Memory Corruption |
| 59936 | Poppler pdftoabw Utility poppler/ABWOutputDev.cc ABWOutputDev::endWord Functi... |
| 59825 | Poppler PDF Handling Multiple Unspecified Overflows |
| id | Description |
|---|---|
| 59184 | Poppler XRef.cc ObjectStream::ObjectStream Function PDF Handling Overflow |
| 59183 | Xpdf XRef.cc ObjectStream::ObjectStream Function PDF Handling Overflow |
| 59182 | Poppler PSOutputDev::doImageL1Sep Function PDF Handling Overflow |
| 59181 | Xpdf PSOutputDev::doImageL1Sep Function PDF Handling Overflow |
| 59180 | Poppler Stream.cc ImageStream::ImageStream Function PDF Handling Overflow |
| 59179 | Xpdf Stream.cc ImageStream::ImageStream Function PDF Handling Overflow |
| 59178 | Poppler SplashBitmap::SplashBitmap Function PDF Handling Overflow |
| 59177 | Xpdf SplashBitmap::SplashBitmap Function PDF Handling Overflow |
| 59176 | Poppler Splash.cc Splash::drawImage Function PDF Handling Arbitrary Code Exec... |
| 59175 | Xpdf Splash.cc Splash::drawImage Function PDF Handling Arbitrary Code Execution |
| 59143 | Poppler glib/poppler-page.cc create_surface_from_thumbnail_data Function Over... |
| 54808 | Poppler JBIG2 Decoder SplashBitmap Handling Overflow |
| 54807 | Poppler JBIG2 Decoder CairoOutputDev Handling Overflow |
| 54489 | Xpdf JBIG2 Decoder PDF File Handling Unitialized Memory Free DoS |
| 54488 | CUPS JBIG2 Decoder PDF File Handling Unitialized Memory Free DoS |
| 54487 | Poppler JBIG2 Decoder PDF File Handling Out-of-bounds Read DoS |
| 54486 | Xpdf JBIG2 Decoder PDF File Handling Out-of-bounds Read DoS |
| 54485 | CUPS JBIG2 Decoder PDF File Handling Out-of-bounds Read DoS |
| 54484 | Poppler JBIG2 Decoder PDF File Handling NULL Dereference DoS |
| 54483 | Xpdf JBIG2 Decoder PDF File Handling NULL Dereference DoS |
Milw0rm Exploits
| id | Description |
|---|---|
| 2008-07-08 | Poppler <= 0.8.4 libpoppler uninitialized pointer Code Execution PoC |









